Analytics Alerts

Browse the Cortex analytics alert reference.

Severity
Detection module
Data source
  • SSO Brute Force Informational Identity Analytics 3 variations

    An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack.

    Activation:
    14 Days
    Training:
    30 Days
    Test:
    1 Hour
    Deduplication:
    1 Day
    ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
    ATT&CK techniques: Brute Force (T1110) Brute Force: Password Guessing (T1110.001) Compromise Accounts (T1586)
    Required data: AzureAD Azure SignIn Log Idira Duo Okta OneLogin PingOne
    Attacker's goals: An attacker is attempting to gain access to an account secured with MFA.
    Investigative actions: Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.

    Variations

    SSO Brute Force on a Honey User Account

    Medium overridden

    An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden

    Successful SSO Brute Force Threat Detected

    Medium overridden

    An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden

    SSO Brute Force Activity Observed

    Low overridden

    An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack. overridden