Analytics
Informational
✕
SSH authentication brute force attempts
A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack.
- Module:
- Identity Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:
Attackers attempt to log in to a remote host.
Investigative actions:
Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.
- Test period:
- 15 Minutes
- Deduplication:
- 3 Hours
2 variations:
- Successful SSH Brute Force Low (parent: Informational)
- Possible SSH Brute Force Low (parent: Informational)