Brute Force T1110

Tactic: Credential Access

Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained. Without knowledge of the password for an account or set of accounts, an adversary may systematically guess the password using a repetitive or iterative mechanism. Brute forcing passwords can take place via interaction with a service that will check the validity of those credentials or offline against previously acquired credential data, such as password hashes.

Events covered

32 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4634An account was logged off.
Security-AuditingEvent ID 4648A logon was attempted using explicit credentials.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Security-AuditingEvent ID 4724An attempt was made to reset an account's password.
Security-AuditingEvent ID 4768A Kerberos authentication ticket (TGT) was requested.
Security-AuditingEvent ID 4771Kerberos pre-authentication failed.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 5152The Windows Filtering Platform blocked a packet.
Security-AuditingEvent ID 5154The Windows Filtering Platform has permitted an application or service to listen on a port for incoming connections.
Security-AuditingEvent ID 5155The Windows Filtering Platform has blocked an application or service from listening on a port for incoming connections.
Security-AuditingEvent ID 5156The Windows Filtering Platform has permitted a connection.
Security-AuditingEvent ID 5157The Windows Filtering Platform has blocked a connection.
Security-AuditingEvent ID 5158The Windows Filtering Platform has permitted a bind to a local port.
Security-AuditingEvent ID 5159The Windows Filtering Platform has blocked a bind to a local port.
Defender-DeviceInfoanyDevice information
Defender-DeviceLogonEventsLogonSuccessLogon succeeded
Defender-DeviceLogonEventsLogonFailedLogon failed
Defender-IdentityInfoanyIdentity information
Linux-AuditdEvent ID 1100USER_AUTH
MSSQLSERVEREvent ID 18456Event ID 18456
MSSQLSERVEREvent ID 33205Event ID 33205
AppLockerEvent ID 8005FilePathBuffer was allowed to run.
NTLMEvent ID 8004NTLM authentication in this domain audit (domain controller): Audit NTLM authentication in this domain.
NTLMEvent ID 8006NTLM authentication in this domain audit (domain controller), event 8006.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
RemoteDesktopServices-RdpCoreTSEvent ID 131The server accepted a new ConnType connection from client ClientIP.
SMBClientEvent ID 31017Rejected an insecure guest logon.

Authoring guide

These 306 rules share fields, values, and exclusions.

Fields filtered most (392 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID46eq 41, in 4, regex_match 14625, 4624, 8004, 4768, 4776
sourcetype46eq 45, in 1aws:cloudtrail, azure:monitor:aad, crowdstrike:identities, o365:management:activity, xmlwineventlog:microsoft-windows-ntlm/operational
EventType33eq 24, in 8, starts_with 7, contains 1user.authentication., user.session.start, ssh_login, user_login, logon-failed
MessageType24eq 240, 2
Channel23eq 23, in 17
data_stream.dataset23eq 22, in 1okta.system, azure.signinlogs, o365.audit, aws.cloudtrail, azure.identity_protection
eventtype19eq 19, contains 1, starts_with 1
isOutlier19eq 191
Codename18eq 18codenamelist, Password Guessing, Password Spraying
Status18eq 15, in 2, contains 10x6, 403, 0x12, 0x18, 0xc0000064
src_ip18eq 8, is_not_null 6, ne 5, cidr_match 3, cross_field_compare 1-, %domain_controllers_ips%, 10.0.0.0/8, 127.0.0.0/8, 127.0.0.1
aws::eventName15eq 15consolelogin, ConsoleLogin, getpassworddata, modifydbinstance, GetObject
LogonType14eq 12, in 1, ne 1Network, Interactive, RemoteInteractive, Unlock
event.category13eq 13authentication, process
TargetUserName12ne 10, eq 2*$, %account_allowed_proxy%, administrator

Top indicator values (983 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
isOutliereq
1
1933
MessageTypeeq
0
1515
MessageTypeeq
2
921
Codenameeq
codenamelist
1212
EventIDeq
4625
1215
EventIDeq
4624
429
EventIDeq
4768
414
event.categoryeq
authentication
1134
TargetUserNamene
*$
1014
LogonTypeeq
Network
941
data_stream.dataseteq
okta.system
948
data_stream.dataseteq
azure.signinlogs
636
event.outcomeeq
failure
923
unique_accountsgt
30
99
EventTypeeq
user.session.start
78
EventTypestarts_with
user.authentication.
78
sourcetypeeq
aws:cloudtrail
759
sourcetypeeq
azure:monitor:aad
747
sourcetypeeq
crowdstrike:identities
66
sourcetypeeq
o365:management:activity
680
sourcetypeeq
xmlwineventlog:microsoft-windows-ntlm/operational
55
aws::eventNameeq
consolelogin
619
security_result.actioneq
BLOCK
617
SChannelNamecross_field_compare
src
55
Workloadeq
azureactivedirectory
530
categoryeq
signinlogs
512
okta::outcome.reasonin
invalid_credentials
55
okta::outcome.reasonin
locked_out
55
properties.authenticationDetails{}.succeededeq
false
55
properties.status.errorCodeeq
50126
55

Exclusions (197 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
src_ipcidr_match
10.0.0.0/8
4
src_ipcidr_match
127.0.0.0/8
4
src_ipcidr_match
169.254.0.0/16
4
src_ipcidr_match
172.16.0.0/12
4
src_ipcidr_match
192.168.0.0/16
4
src_ipeq
%domain_controllers_ips%
3
Statusin
0xc000005e
2
Statusin
0xc00000dc
2
Statusin
0xc0000133
2
Statusin
0xc000015b
2
Statusin
0xc0000192
2
TO_IP(source.ip)cidr_match
127.0.0.0/8
2
TO_IP(source.ip)cidr_match
::1
2
azure.identityprotection.properties.risk_statein
confirmedsafe
2
azure.identityprotection.properties.risk_statein
dismissed
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 38 rules

Elastic 42 rules

Splunk 77 rules

Kusto 102 rules

YARA-L 14 rules

Panther 33 rules