Analytics Informational

Multiple failed logins from a single IP

Multiple failed logins were observed in a short period of time from a single external IP. The IP is not a known identity provider.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log, Azure Audit Log, Gcp Audit Log
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Trusted Relationship (T1199) Valid Accounts: Cloud Accounts (T1078.004)
Attacker's goals:

Gain initial access to the cloud console.

Investigative actions:

Check if the IP is a known IP. Check if a successful login from the same IP occurred after the failed login attempts.

Test period:
1 Hour
Deduplication:
5 Days
2 variations:
  • Multiple failed logins from an unknown IP Medium (parent: Informational)
  • Multiple failed logins from a single IP by a compromised AWS access key High (parent: Informational)