Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source

1 alert match the current filters. tactic: TA0006 ✕

Download CSV Show ATT&CK heatmap
  • Possible external RDP Brute-Force Low Identity Analytics 2 variations

    Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    10 Minutes
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Brute Force: Password Guessing (T1110.001)
    Required data: XDR Agent
    Attacker's goals: The attacker attempts to gain access to the accounts.
    Investigative actions: If the source IP is an internal IP, adjust network IP ranges. Identify the user performing RDP and check that it is authorized. Check whether this IP has a malicious reputation. Reset the user's password. Follow further actions done by the user.

    Variations

    Possible external RDP Brute-Force on a Honey User Account

    Medium overridden

    Multiple failed remote logins originated from an external IP with at least one successful login. This may indicate a successful brute-force attack. overridden

    Potential External Brute-Force via RDP on Sensitive User

    Medium overridden

    Multiple failed remote logins from an external IP with a sensitive user and at least one successful login. This may indicate a successful brute-force attack. overridden