Analytics Low

NTLM Brute Force on a Service Account

A service account attempted to authenticate to a target using NTLM an excessive number of times in a short period. This may indicate a NTLM brute-force attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:

The attacker attempts to gain access to the service accounts.

Investigative actions:

Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.

Test period:
10 Minutes
Deduplication:
1 Day