An enterprise computer network is monitored to detect and neutralize security breaches. In a first case failed login attempts to multiple target machines are noted and if they come from one machine or a small number of originating machines, a password spraying attack from the originating machines is indicated, resulting in the originating machines being segregated from the system. In another case, multiple indicators of compromise are used to determine whether an enterprise machine is infected with malware and only if multiple indicators are present is the machine segregated from the system.