Analytics
Low
✕
Excessive user account lockouts
A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110) Brute Force: Password Spraying (T1110.003)
Attacker's goals:
An attacker may be attempting to gain unauthorized access to user accounts.
Investigative actions:
Investigate the associated authentication attempts and login failures (e.g. 4740, 4625, 4776 events). Determine if any programs have stored outdated credentials, causing account lockouts. Find the computer responsible for the lockouts and verify if it exists on the domain. Monitor services that may be running with a user's credentials.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
2 variations:
- Excessive user account lockouts from a suspicious source Medium (parent: Low)
- Excessive account lockouts on suspicious users Medium (parent: Low)