Analytics
Informational
✕
Possible Password Spray in universal authentication
An abnormally high amount of universal authentication attempts were seen within a short period of time. This may indicate a password spray attack.
- Module:
- Identity Analytics
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
ATT&CK techniques: Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001) Compromise Accounts: Cloud Accounts (T1586.003)
Attacker's goals:
An attacker may be attempting to gain unauthorized access to user accounts.
Investigative actions:
Determine whether this was part of a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
4 variations:
- Possible Password Spray in universal authentication Involving a Honey User Medium (parent: Informational)
- Suspicious Password Spray in universal authentication Medium (parent: Informational)
- Password Spray in universal authentication Low (parent: Informational)
- Possible Password Spray in universal authentication with successful authentication Informational