Identify Source of Brute Force Attacks

Investigate how hackers are managing to attempt brute force attacks on a WordPress login despite /wp-login.php being locked down; the answer was via /xmlrpc.php which can be blocked by using Deny All Firewall plugin.