Analytics Informational

Possible Brute Force in universal authentication

An abnormally high amount of authentication attempts via universal authentication were seen within a short period of time. This may indicate a brute-force attack.

Module:
Identity Analytics
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
ATT&CK techniques: Brute Force (T1110) Brute Force: Password Guessing (T1110.001) Compromise Accounts: Cloud Accounts (T1586.003)
Attacker's goals:

An attacker is attempting to gain access to an account secured with MFA.

Investigative actions:

Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.

Test period:
1 Hour
Deduplication:
1 Day
4 variations:
  • Possible Brute Force in universal authentication on a honey user Medium (parent: Informational)
  • Suspicious Brute Force in universal authentication Medium (parent: Informational)
  • Brute Force in universal authentication Low (parent: Informational)
  • Abnormal Possible Brute Force in universal authentication Informational