Analytics
Low
✕
NTLM Brute Force on an Administrator Account
An administrator account attempted to authenticate using NTLM to a target an excessive number of times in a short period. This may indicate an NTLM brute-force attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:
The attacker attempts to gain access to the administrator accounts.
Investigative actions:
Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.
- Test period:
- 10 Minutes
- Deduplication:
- 1 Day