Analytics Informational

SSO Password Spray

An abnormally high amount of SSO authentication attempts were seen within a short period of time. This may have resulted from a login password spray attack.

Module:
Identity Analytics
Data source:
AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne
ATT&CK tactics: Credential Access (TA0006) Resource Development (TA0042)
ATT&CK techniques: Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001) Compromise Accounts (T1586)
Attacker's goals:

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions:

See whether this was a legitimate action. Check if the user usually logs in from this country. Check whether a successful login was made after unsuccessful attempts.

Test period:
1 Hour
Deduplication:
1 Day
3 variations:
  • SSO Password Spray Involving a Honey User Medium (parent: Informational)
  • SSO Password Spray Threat Detected Medium (parent: Informational)
  • SSO Password Spray Activity Observed Low (parent: Informational)