Analytics
Low
✕
Multiple user accounts failed login due to account lockouts
A high amount of user accounts were locked out from a single source host in a short time period. This may be the result of a brute-force or password spray attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110) Brute Force: Password Spraying (T1110.003)
Attacker's goals:
An attacker may be attempting to gain unauthorized access to user accounts.
Investigative actions:
Investigate the associated authentication attempts and login failures (e.g. 4740, 4625, 4776 events). Check if any programs were cached with old credentials, resulting in account lockouts. Find the computer responsible for the lockouts and verify if it exists on the domain. Monitor services that may be running with a user's credentials.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
1 variation:
- Excessive user account login failure due to lockout from a suspicious source Medium (parent: Low)