Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapPossible external RDP Brute-Force Low Identity Analytics 2 variations
Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 10 Minutes
- Deduplication:
- 1 Day
ATT&CK tactics: Credential Access (TA0006)ATT&CK techniques: Brute Force: Password Guessing (T1110.001)Required data: XDR AgentAttacker's goals: The attacker attempts to gain access to the accounts.Investigative actions: If the source IP is an internal IP, adjust network IP ranges. Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.Variations
Possible external RDP Brute-Force on a Honey User Account
Medium overridden
Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. overridden
Potential External Brute-Force via RDP on Sensitive User
Medium overridden
Multiple failed remote logins from an external IP with a sensitive user and at least one successful login. This may indicate a successful brute-force attack. overridden