Analytics Informational

SSH authentication brute force attempts

A user attempted to authenticate via SSH an excessive number of times in a short period. This may indicate a brute force attack.

Module:
Identity Analytics
Data source:
XDR Agent
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force (T1110)
Attacker's goals:

Attackers attempt to log in to a remote host.

Investigative actions:

Verify any successful authentication by the user account referenced by the alert, as these can indicate the attacker managed to guess the credentials.

Test period:
15 Minutes
Deduplication:
3 Hours
2 variations:
  • Successful SSH Brute Force Low (parent: Informational)
  • Possible SSH Brute Force Low (parent: Informational)