EE does not seem to have any nginx location configs for xmlrpc attacks, any suggestions on how best to deal with these?

For anyone who wants to prevent the xmlrpc Brute Force Attack, you can simply deny all access to the file via nginx:

location = /xmlrpc.php {
    deny all;

Warning: this will prevent some third party services (valutpress) from working.

Nice one, also you can delete xmlrpc.php if not needed.

