AN1275
Analytic 1275
Windows
High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe
WinEventLog:Security
EventCode=4776, 4625
[TimeWindow]
Adjustable window to correlate failed logons, e.g., 5-10 minutes
[UserContext]
Define scope of monitored users (e.g., service accounts, admins)
[FailureThreshold]
Count of failed logons before raising an alert (e.g., 10-15)
AN1276
Analytic 1276
Linux
Multiple authentication failures for valid or invalid users followed by success from same IP/user
auditd:USER_LOGIN
USER_AUTH
[TimeWindow]
Period of brute force activity correlation (e.g., 5 mins)
[IPWhitelist]
Exclude known monitoring IPs or jump boxes
[LoginSource]
Filter SSH vs. local logins
AN1277
Analytic 1277
Identity Provider
Password spraying or brute force attempts across user pool within short time intervals
azure:signinlogs
Sign-in logs
[UsernameSprayThreshold]
Max number of accounts targeted from a single IP
[GeoAnomaly]
Mismatch between user location and request location
AN1278
Analytic 1278
macOS
Multiple failed authentications in unified logs (e.g., loginwindow or sshd)
macos:unifiedlog
auth
[TimeWindow]
Scope of authentication failures (e.g., 10-15 mins)
[TargetUser]
Filter known service or decoy accounts
AN1279
Analytic 1279
SaaS
Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.
m365:unified
Sign-in logs
[AppName]
Detect brute force attempts targeting specific apps
[UserGroup]
Limit alert scope to high-value user groups