Analytics Informational

Intense SSO failures

An abnormally high amount of SSO authentication attempts were seen within a short period of time. This could be the outcome of a brute-force login attempt.

Module:
Identity Analytics
Data source:
AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne
ATT&CK tactics: Credential Access (TA0006) Initial Access (TA0001)
ATT&CK techniques: Valid Accounts (T1078) Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001)
Attacker's goals:

An attacker is attempting to gain access to an account secured with MFA.

Investigative actions:

Check the legitimacy of this activity and determine whether it is malicious or not. Check whether a successful login was made after unsuccessful attempts.

Test period:
10 Minutes
Deduplication:
1 Day
1 variation:
  • Intense SSO failures with suspicious characteristics Low (parent: Informational)