For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible Password Spray in universal authentication

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Detection Modules

Identity Analytics

ATT&CK Tactic

Credential Access (TA0006), Resource Development (TA0042)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001), Compromise Accounts: Cloud Accounts (T1586.003)

Severity

Informational

Description

An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Determine whether this was part of a legitimate action.

  • Check if the user usually logs in from this country.

  • Check whether a successful login was made after unsuccessful attempts.

Variations

Password Spray in universal authentication involving a honey user

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Resource Development (TA0042)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001), Compromise Accounts: Cloud Accounts (T1586.003)

Severity

Medium

Description

An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Determine whether this was part of a legitimate action.

  • Check if the user usually logs in from this country.

  • Check whether a successful login was made after unsuccessful attempts.

Suspicious Password Spray in universal authentication

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Resource Development (TA0042)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001), Compromise Accounts: Cloud Accounts (T1586.003)

Severity

Medium

Description

An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Determine whether this was part of a legitimate action.

  • Check if the user usually logs in from this country.

  • Check whether a successful login was made after unsuccessful attempts.

Password Spray in universal authentication

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Resource Development (TA0042)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001), Compromise Accounts: Cloud Accounts (T1586.003)

Severity

Low

Description

An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Determine whether this was part of a legitimate action.

  • Check if the user usually logs in from this country.

  • Check whether a successful login was made after unsuccessful attempts.

Possible Password Spray in universal authentication with successful authentication

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006), Resource Development (TA0042)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001), Compromise Accounts: Cloud Accounts (T1586.003)

Severity

Informational

Description

An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Determine whether this was part of a legitimate action.

  • Check if the user usually logs in from this country.

  • Check whether a successful login was made after unsuccessful attempts.

Was this helpful?