Multiple failed logins from a single IP
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Initial Access (TA0001)
ATT&CK Technique
Trusted Relationship (T1199), Valid Accounts: Cloud Accounts (T1078.004)
Severity
Informational
Description
Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider.
Attacker's Goals
Gain initial access to the cloud console.
Investigative actions
Check if the IP is a known IP.
Check if a successful login from the same IP occurred after the failed login attempts.
Variations
PreviousMultiple failed AWS assume role attempts
NextMultiple mail items were accessed in a short period of time
Was this helpful?
