Analytics
Informational
✕
VPN Login Password Spray
An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack.
- Module:
- Identity Analytics
- Data source:
- Palo Alto Networks Global Protect, Third-Party VPNs
ATT&CK tactics: Credential Access (TA0006)
ATT&CK techniques: Brute Force: Password Spraying (T1110.003) Brute Force: Password Guessing (T1110.001)
Attacker's goals:
An attacker may be attempting to gain unauthorized access to user accounts.
Investigative actions:
Analyze the time intervals between login attempts to check for patterns indicative of a password spraying attack. Investigate the cause of the login failures (e.g. incorrect passwords, account lockouts, other factors). Review the geographic regions behind the failed login attempts. Investigate if a successful login was made after unsuccessful attempts. Cross-reference the IP address with threat intelligence sources to see if it is associated with known malicious activity.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day
2 variations:
- Successful VPN Password Spray Threat Detected with unusual characteristics Medium (parent: Informational)
- VPN login password spray with unusual characteristics Low (parent: Informational)