Analytics
Informational
✕
SSO Brute Force
An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a brute-force attack.
- Module:
- Identity Analytics
- Data source:
- AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
ATT&CK techniques: Brute Force (T1110) Brute Force: Password Guessing (T1110.001) Compromise Accounts (T1586)
Attacker's goals:
An attacker is attempting to gain access to an account secured with MFA.
Investigative actions:
Check the legitimacy of this activity and determine whether it is malicious or not. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
3 variations:
- SSO Brute Force on a Honey User Account Medium (parent: Informational)
- Successful SSO Brute Force Threat Detected Medium (parent: Informational)
- SSO Brute Force Activity Observed Low (parent: Informational)