Analytics
Informational
✕
NTLM Brute Force
A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:
The attacker attempts to gain access to the accounts.
Investigative actions:
Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day
2 variations:
- NTLM brute force on a sensitive user Medium (parent: Informational)
- High-frequency NTLM brute force attempts detected Low (parent: Informational)