For the complete documentation index, see llms.txt. This page is also available as Markdown.

External Login Password Spray

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

XDR Agent

Detection Modules

Identity Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Informational

Description

An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

Variations

External Login Password Spray Involving a Honey User

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Medium

Description

An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

External Login Password Spray from Multiple Source Hosts

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Informational

Description

An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

Successful External Login Password Spray on a Domain Controller

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Medium

Description

An abnormally high amount of user account login attempts were seen on a domain controller within a short period of time.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

Successful External Login Password Spray on a sensitive server

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Medium

Description

An abnormally high amount of user account login attempts were seen on a sensitive server within a short period of time.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

Successful External Login Password Spray

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Low

Description

An abnormally high amount of user account login attempts were seen on a host within a short period of time. This may have resulted from a login password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

External Login Password Spray on a Domain Controller

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003)

Severity

Low

Description

An abnormally high amount of user account login attempts were seen on a domain controller within a short period of time.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Check the amount of time in between each login attempt.

  • Investigate the reason behind the login failures and if any accounts were locked out.

  • Look for any successful login attempts and the ratio of login success versus login failures.

Was this helpful?