Analytics Informational

NTLM Brute Force

A user account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate an NTLM brute force attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:

The attacker attempts to gain access to the accounts.

Investigative actions:

Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.

Test period:
10 Minutes
Deduplication:
1 Day
2 variations:
  • NTLM brute force on a sensitive user Medium (parent: Informational)
  • High-frequency NTLM brute force attempts detected Low (parent: Informational)