For the complete documentation index, see llms.txt. This page is also available as Markdown.

VPN Login Password Spray

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

1 Day

Required Data

Requires one of the following data sources: Palo Alto Networks Global Protect OR Third-Party VPNs

Detection Modules

Identity Analytics

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001)

Severity

Informational

Description

An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Analyze the time intervals between login attempts to check for patterns indicative of a password spraying attack.

  • Investigate the cause of the login failures (e.g. incorrect passwords, account lockouts, other factors).

  • Review the geographic regions behind the failed login attempts.

  • Investigate if a successful login was made after unsuccessful attempts.

  • Cross-reference the IP address with threat intelligence sources to see if it is associated with known malicious activity.

Variations

Successful VPN Password Spray Threat Detected with unusual characteristics

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001)

Severity

Medium

Description

An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Analyze the time intervals between login attempts to check for patterns indicative of a password spraying attack.

  • Investigate the cause of the login failures (e.g. incorrect passwords, account lockouts, other factors).

  • Review the geographic regions behind the failed login attempts.

  • Investigate if a successful login was made after unsuccessful attempts.

  • Cross-reference the IP address with threat intelligence sources to see if it is associated with known malicious activity.

VPN login password spray with unusual characteristics

Synopsis

Field
Value

ATT&CK Tactic

Credential Access (TA0006)

ATT&CK Technique

Brute Force: Password Spraying (T1110.003), Brute Force: Password Guessing (T1110.001)

Severity

Low

Description

An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack.

Attacker's Goals

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions

  • Analyze the time intervals between login attempts to check for patterns indicative of a password spraying attack.

  • Investigate the cause of the login failures (e.g. incorrect passwords, account lockouts, other factors).

  • Review the geographic regions behind the failed login attempts.

  • Investigate if a successful login was made after unsuccessful attempts.

  • Cross-reference the IP address with threat intelligence sources to see if it is associated with known malicious activity.

Was this helpful?