Created a detection rule to identify failed Remote Desktop (RDP) login attempts using Elastic Security. Investigated Windows Event ID 4625 and analyzed attack attempts through Kibana dashboards.