Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • SSH authentication brute force attempts Informational Identity Analytics 2 variations

    A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    15 Minutes
    Deduplication:
    3 Hours
    ATT&CK tactics: Credential Access (TA0006)
    ATT&CK techniques: Brute Force (T1110)
    Required data: XDR Agent
    Attacker's goals: Attackers attempt to log in to a remote host.
    Investigative actions: Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.

    Variations

    Successful SSH Brute Force

    Low overridden

    A user successfully authenticated via SSH after an excessive number of failures in a short period. overridden

    Possible SSH Brute Force

    Low overridden

    A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack. overridden