Analytics Low

NTLM Brute Force on an Administrator Account

An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:

The attacker attempts to gain access to the administrator accounts.

Investigative actions:

Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.

Test period:
10 Minutes
Deduplication:
1 Day