Analytics Informational

VPN Login Password Spray

An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack.

Module:
Identity Analytics
Data source:
Palo Alto Networks Global Protect, Third-Party VPNs
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001)
Attacker's goals:

An attacker may be attempting to gain unauthorized access to user accounts.

Investigative actions:

Analyze the time intervals between login attempts to check for patterns indicative of a password spraying attack. Investigate the cause of the login failures (e.g. incorrect passwords, account lockouts, other factors). Review the geographic regions behind the failed login attempts. Investigate if a successful login was made after unsuccessful attempts. Cross-reference the IP address with threat intelligence sources to see if it is associated with known malicious activity.

Test period:
1 Hour
Deduplication:
1 Day
2 variations:
  • Successful VPN Password Spray Threat Detected with unusual characteristics Medium (parent: Informational)
  • VPN login password spray with unusual characteristics Low (parent: Informational)