Detection rules › Sigma

Failed Console Login

Status
test
Severity
low
Log source
product aws, service cloudtrail
Author
Zach Mathis (@yamatosecurity)
Source
github.com/Yamato-Security/suzaku-rules

Detects failed console login attempts, which may indicate an attacker attempting to gain access to

MITRE ATT&CK coverage

TacticTechniques
Initial AccessNo specific technique

Telemetry coverage

Rules detecting the same action

These rules filter on the same operation.

Rule body

title: Failed Console Login
id: 978c15f1-3468-42b2-bf0f-bb29ae6168cc
status: test
description: Detects failed console login attempts, which may indicate an attacker attempting to gain access to
references:
author: Zach Mathis (@yamatosecurity)
date: 2025-08-02
modified: 2025-08-02
tags:
    - attack.initial_access
logsource:
    product: aws
    service: cloudtrail
detection:
    selection:
        eventSource: signin.amazonaws.com
        eventName: 'ConsoleLogin'
        responseElements.ConsoleLogin: 'Failure'
    condition: selection
level: low

Stages and Predicates

Stage 0: condition

selection

Stage 1: selection

selection:
    eventSource: signin.amazonaws.com
    eventName: 'ConsoleLogin'
    responseElements.ConsoleLogin: 'Failure'

Indicators

These rows show field, operator, and value matches.