Cross-source coverage
T1110 / ATT&CK
Brute Force
322 rules · 319 families across 9 sources.
5 deprecated hidden · include
From MITRE ATT&CK 19.2
Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.
Brute forcing credentials may take place at various points during a breach. For example, adversaries may attempt to brute force access to Valid Accounts within a victim environment leveraging knowledge gathered from other post-compromise behaviors such as OS Credential Dumping, Account Discovery, or Password Policy Discovery. Adversaries may also combine brute forcing activity with behaviors such as External Remote Services as part of Initial Access.
If an adversary guesses the correct password but fails to login to a compromised account due to location-based conditional access policies, they may change their infrastructure until they match the victim’s location and therefore bypass those policies.
- Tactics
- Credential Access
- Platforms
- Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:Securityauditd:USER_LOGINazure:signinlogsmacos:unifiedlogm365:unified
How MITRE says to detect it DET0463
Brute Force Authentication Failures with Multi-Platform Log Correlation
Windows Analytic 1275
High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe
WinEventLog:SecurityEventCode=4776, 4625
Linux Analytic 1276
Multiple authentication failures for valid or invalid users followed by success from same IP/user
auditd:USER_LOGINUSER_AUTH
Identity Provider Analytic 1277
Password spraying or brute force attempts across user pool within short time intervals
azure:signinlogsSign-in logs
macOS Analytic 1278
Multiple failed authentications in unified logs (e.g., loginwindow or sshd)
macos:unifiedlogauth
SaaS Analytic 1279
Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.
m365:unifiedSign-in logs
Sub-techniques with coverage
Counted in the 322 above — a rule tagged a sub-technique covers this technique too.
Wazuh Core Ruleset
97 rules · 94 families| Detection | Severity | Format |
|---|---|---|
| Apache: Multiple authentication failures with invalid user. | High | Wazuh XML |
| ASA: Multiple AAA (VPN) authentication failures. | High | Wazuh XML |
| Asterisk: Multiple failed logins. 2 variants | High | Wazuh XML |
| Asterisk: Multiple failed logins. 2 variants | High | Wazuh XML |
| AWS Cloudtrail: - - Possible break in attempt (high number of login attempts). · rule 80255 | High | Wazuh XML |
| AWS S3 multiple authentication failures. | High | Wazuh XML |
| by a success. | High | Wazuh XML |
| CiscoVPN: Multiple VPN authentication failures. | High | Wazuh XML |
| Courier brute force (multiple failed logins). | High | Wazuh XML |
| Courier: Multiple connection attempts from same source. | High | Wazuh XML |
+ 87 more from Wazuh Core Ruleset → showing the 10 highest-severity
splunk/security_content
72 rules| Detection | Severity | Format |
|---|---|---|
| ASL AWS Credential Access GetPasswordData | Undefined | SPL |
| ASL AWS Credential Access RDS Password reset | Undefined | SPL |
| ASL AWS IAM Assume Role Policy Brute Force | Undefined | SPL |
| AWS Credential Access Failed Login | Undefined | SPL |
| AWS Credential Access GetPasswordData | Undefined | SPL |
| AWS Credential Access RDS Password reset | Undefined | SPL |
| AWS High Number Of Failed Authentications From Ip | Undefined | SPL |
| AWS IAM Assume Role Policy Brute Force | Undefined | SPL |
| AWS Multiple Users Failing To Authenticate From Ip | Undefined | SPL |
| AWS Unusual Number of Failed Authentications From Ip | Undefined | SPL |
+ 62 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
40 rules| Detection | Severity | Format |
|---|---|---|
| AWS Management Console Brute Force of Root User Identity | High | Elastic TOML |
| Entra ID Excessive Account Lockouts Detected | High | Elastic TOML |
| Entra ID Protection - Risk Detection - Sign-in Risk | High | Elastic TOML |
| Entra ID Protection - Risk Detection - User Risk | High | Elastic TOML |
| Entra ID Sign-in TeamFiltration User-Agent Detected | High | Elastic TOML |
| Multiple SonicWall Login Failures Followed by Successful Login | High | Elastic TOML |
| Okta Successful Login After Credential Attack | High | Elastic TOML |
| Potential Successful SSH Brute Force Attack | High | Elastic TOML |
| Attempts to Brute Force an Okta User Account | Medium | Elastic TOML |
| AWS IAM Principal Enumeration via UpdateAssumeRolePolicy | Medium | Elastic TOML |
+ 30 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
28 rules| Detection | Severity | Format |
|---|---|---|
| External Remote SMB Logon from Public IP | High | Sigma |
| HackTool - CrackMapExec Execution | High | Sigma |
| HackTool - Hashcat Password Cracker Execution | High | Sigma |
| HackTool - Hydra Password Bruteforce Execution | High | Sigma |
| Hack Tool User Agent | High | Sigma |
| Password Spray Activity | High | Sigma |
| Potential MFA Bypass Using Legacy Client Authentication | High | Sigma |
| Sign-in Failure Due to Conditional Access Requirements Not Met | High | Sigma |
| Use of Legacy Authentication Protocols | High | Sigma |
| Account Lockout | Medium | Sigma |
+ 18 more from SigmaHQ/sigma → showing the 10 highest-severity
panther-labs/panther-analysis
27 rules| Detection | Severity | Format |
|---|---|---|
| Azure Excessive Account Lockouts | High | Panther Python |
| Failed Root Console Login | High | Panther Python |
| GSuite Workspace Password Reuse Has Been Enabled | High | Panther Python |
| GSuite Workspace Strong Password Enforcement Has Been Disabled | High | Panther Python |
| Netskope Many Unauthorized API Calls | High | Panther Python |
| OpenAI Brute Force Login Success | High | Panther Python |
| Admin logged out because of successive login failures | Medium | Panther Python |
| Anthropic SSO Login Failed | Medium | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| Azure Many Failed SignIns | Medium | Panther Python |
+ 17 more from panther-labs/panther-analysis → showing the 10 highest-severity
Azure/Azure-Sentinel
25 rules| Detection | Severity | Format |
|---|---|---|
| Brute force attack against user credentials (Uses Authentication Normalization) | Medium | KQL |
| Failed AWS Console logons but success logon to AzureAD | Medium | KQL |
| Failed AzureAD logons but success logon to AWS Console | Medium | KQL |
| Failed AzureAD logons but success logon to host | Medium | KQL |
| Failed host logons but success logon to AzureAD | Medium | KQL |
| High count of failed attempts from same client IP | Medium | KQL |
| High count of failed logons by a user | Medium | KQL |
| IP with multiple failed Microsoft Entra ID logins successfully logs in to Palo Alto VPN | Medium | KQL |
| New country signIn with correct password | Medium | KQL |
| Potential Password Spray Attack (Uses Authentication Normalization) | Medium | KQL |
+ 15 more from Azure/Azure-Sentinel → showing the 10 highest-severity
socfortress/Wazuh-Rules
15 rules| Detection | Severity | Format |
|---|---|---|
| Brute-force SSH attempt with sshpass targeting localhost (T1110.004 - Credential Stuffing) | High | Wazuh XML |
| Credential stuffing attempt using sshpass inside shell script (T1110.004) | High | Wazuh XML |
| Possible sudo brute-force detected: use of 'sudo -S whoami' | High | Wazuh XML |
| Sysmon - Event 1: Process creation · AzureAD Brute Force (T1110.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · DomainPasswordSpray.ps1 Execution (T1110.003) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · ESXi SSH Brute Force (T1110.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Hashcat Password Cracking (T1110.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Kerbrute Credential Stuffing (T1110.004) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · Kerbrute Execution (T1110.001) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · LDAP Brute Force PowerShell (T1110.001) | High | Wazuh XML |
+ 5 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
chronicle/detection-rules
14 rules| Detection | Severity | Format |
|---|---|---|
| aws_guardduty_brute_force_activity_detected | High | YARA-L |
| onelogin_otp_brute_force_attack | High | YARA-L |
| aws_unusual_number_of_failed_authentications_from_the_same_ip | Medium | YARA-L |
| okta_mfa_brute_force_attack | Medium | YARA-L |
| okta_threatinsight_login_failure_with_high_unknown_users | Medium | YARA-L |
| okta_threatinsight_suspected_brute_force_attack | Medium | YARA-L |
| okta_threatinsight_suspected_password_spray_attack | Medium | YARA-L |
| okta_threatinsight_targeted_brute_force_attack | Medium | YARA-L |
| okta_user_rejected_multiple_push_notifications | Medium | YARA-L |
| rw_windows_password_spray_T1110_003 | Medium | YARA-L |
+ 4 more from chronicle/detection-rules → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
4 rules| Detection | Severity | Format |
|---|---|---|
| Kerberos attacks | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Multiple Accounts Locked | Undefined | KQL |
| Password change after succesful brute force | Undefined | KQL |