Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. technique: T1078 ✕

Download CSV Show ATT&CK heatmap
  • Multiple failed logins from a single IP Informational Cloud 2 variations

    Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    5 Days
    ATT&CK tactics: Initial Access (TA0001)
    ATT&CK techniques: Trusted Relationship (T1199) Valid Accounts: Cloud Accounts (T1078.004)
    Required data: AWS Audit Log Azure Audit Log Gcp Audit Log
    Attacker's goals: Gain initial access to the cloud console.
    Investigative actions: Check if the IP is a known IP. Check if a successful login from the same IP occurred after the failed login attempts.

    Variations

    Multiple failed logins from an unknown IP

    Medium overridden

    Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. The IP is not a known IP in the organization. This could indicate on an active brute force attempt. overridden

    Multiple failed logins from a single IP by a compromised AWS access key

    High overridden

    Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider. overridden