Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0463 — Brute Force Authentication Failures with Multi-Platform Log Correlation
DET0463

Brute Force Authentication Failures with Multi-Platform Log Correlation

5 analytic(s) · 1 technique(s) detected

Analytics

5
AN1275 Analytic 1275
Windows

High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe

WinEventLog:Security EventCode=4776, 4625
[TimeWindow] Adjustable window to correlate failed logons, e.g., 5-10 minutes
[UserContext] Define scope of monitored users (e.g., service accounts, admins)
[FailureThreshold] Count of failed logons before raising an alert (e.g., 10-15)
AN1276 Analytic 1276
Linux

Multiple authentication failures for valid or invalid users followed by success from same IP/user

auditd:USER_LOGIN USER_AUTH
[TimeWindow] Period of brute force activity correlation (e.g., 5 mins)
[IPWhitelist] Exclude known monitoring IPs or jump boxes
[LoginSource] Filter SSH vs. local logins
AN1277 Analytic 1277
Identity Provider

Password spraying or brute force attempts across user pool within short time intervals

azure:signinlogs Sign-in logs
[UsernameSprayThreshold] Max number of accounts targeted from a single IP
[GeoAnomaly] Mismatch between user location and request location
AN1278 Analytic 1278
macOS

Multiple failed authentications in unified logs (e.g., loginwindow or sshd)

macos:unifiedlog auth
[TimeWindow] Scope of authentication failures (e.g., 10-15 mins)
[TargetUser] Filter known service or decoy accounts
AN1279 Analytic 1279
SaaS

Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.

m365:unified Sign-in logs
[AppName] Detect brute force attempts targeting specific apps
[UserGroup] Limit alert scope to high-value user groups

Detected Techniques

1

Credential Access (1)

Details

MITRE ID
DET0463
STIX ID
x-mitre-detection-strategy--1439efe8-4d10-4ce8-8727-458db69bae85
Analytics
5
Techniques Detected
1
By Tactic
Credential Access
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.