Detection rules › By event
Microsoft-Windows-Security-Auditing Event ID 4625
Sigma (11)
- Account Tampering - Suspicious Failed Logon Reasons
- Active Directory honeypot used for lateral movement
- Brutforce enumeration on Windows OpenSSH server with non existing user
- Brutforce enumeration with non existing users (login)
- Brutforce on Windows OpenSSH server with valid users
- Brutforce with denied access due to account restrictions policies
- Detection of default a Windows host name in login attempts
- Failed Logon From Public IP
- Hacktool Ruler
- Metasploit SMB Authentication
- Scanner PoC for CVE-2019-0708 RDP RCE Vuln
Elastic (6)
Splunk (15)
- Detect Password Spray Attack Behavior From Source
- Detect Password Spray Attack Behavior On User
- Detect Password Spray Attempts
- Meterpreter Reverse Shell (Windows Event Log)
- Multiple Failed Network Logon Attempts from Host (Windows Event Log)
- Password Spraying Windows (Windows Event Log)
- Potential EternalBlue via Metasploit (Windows Event Log)
- RDP Brute-force Detection (Windows Event Log)
- Suspicious Login Failures (Windows Event Log)
- Windows Identify PowerShell Web Access IIS Pool
- Windows Local Administrator Credential Stuffing
- Windows Multiple Users Failed To Authenticate From Process
- Windows Multiple Users Remotely Failed To Authenticate From Host
- Windows Unusual Count Of Users Failed To Authenticate From Process
- Windows Unusual Count Of Users Remotely Failed To Auth From Host
Kusto (13)
- Brute force attack against user credentials (Uses Authentication Normalization)
- EatonForeseer - Unauthorized Logins
- Excessive Windows Logon Failures
- Failed host logons but success logon to AzureAD
- Failed logon attempts by valid accounts within 10 mins
- Password Spray
- Password Spraying
- Potential NTLM Relay Attack to Domain Controller
- Potential Password Spray Attack (Uses Authentication Normalization)
- Potential Remote Desktop Tunneling
- SecurityEvent - Multiple authentication failures followed by a success
- Sign-ins from IPs that attempt sign-ins to disabled accounts (Uses Authentication Normalization)
- User login from different countries within 3 hours (Uses Authentication Normalization)
YARA-L (12)
- ADFS DKM Key Access
- GCP_Uunauthorized_GKE_Pod_Token_Endpoint_Usage
- GeoIP User Login From Multiple States Or Countries
- Logins From Terminated Employees
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One
- MITRE ATT&CK T1110.001 Windows Repeated Authentication Failures Before Successful One With User Entity
- MITRE ATT&CK T1110.003 RW Windows Password Spray
- Okta Multiple Failed Requests To Access Applications
- sap break glass account login
- sap impossible travel
- sap multi terminal logon
- Windows Short Term Account Use