Analytics
Informational
✕
Possible Brute-Force attempt
A user account attempted to authenticate to a target an excessive number of times in a short period. This may indicate a brute-force attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006) Lateral Movement (TA0008)
ATT&CK techniques: Brute Force (T1110) Remote Services (T1021)
Attacker's goals:
The attacker attempts to gain access to the accounts.
Investigative actions:
Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.
- Test period:
- 15 Minutes
- Deduplication:
- 1 Day
2 variations:
- Possible Brute-Force attempt on a Honey User Account Medium (parent: Informational)
- Possible Brute-Force attempt with a successful login and suspicious characteristics Low (parent: Informational)