Detection rules › Splunk
AWS Multiple Users Failing To Authenticate From Ip
The following analytic identifies a single source IP failing to authenticate into the AWS Console with 30 unique valid users within 10 minutes. It leverages CloudTrail logs to detect multiple failed login attempts from the same IP address. This behavior is significant as it may indicate a Password Spraying attack, where an adversary attempts to gain unauthorized access or elevate privileges by trying common passwords across many accounts. If confirmed malicious, this activity could lead to unauthorized access, data breaches, or further exploitation within the AWS environment.
Known false positives
- No known false postives for this detection. Please review this alert
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Credential Access |
Telemetry coverage
Rules detecting the same action
These rules filter on the same operation.
- AWS Console Login (Panther)
- AWS Console Login Failed During MFA Challenge (Splunk)
- AWS ConsoleLogin Failed Authentication (Sigma)
- AWS CreateLoginProfile (Splunk)
- AWS Credential Access Failed Login (Splunk)
- AWS High Number Of Failed Authentications For User (Splunk)
- AWS High Number Of Failed Authentications From Ip (Splunk)
- AWS Multiple Failed MFA Requests For User (Splunk)
Rule body
name: AWS Multiple Users Failing To Authenticate From Ip
id: 71e1fb89-dd5f-4691-8523-575420de4630
version: 11
creation_date: '2022-09-26'
modification_date: '2026-05-13'
author: Bhavin Patel
status: production
type: Anomaly
description: The following analytic identifies a single source IP failing to authenticate into the AWS Console with 30 unique valid users within 10 minutes. It leverages CloudTrail logs to detect multiple failed login attempts from the same IP address. This behavior is significant as it may indicate a Password Spraying attack, where an adversary attempts to gain unauthorized access or elevate privileges by trying common passwords across many accounts. If confirmed malicious, this activity could lead to unauthorized access, data breaches, or further exploitation within the AWS environment.
data_source:
- AWS CloudTrail ConsoleLogin
search: |-
`cloudtrail` eventName=ConsoleLogin action=failure
| bucket span=10m _time
| rename user_name as user
| stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent
BY _time, src, signature,
dest, vendor_account, vendor_region,
vendor_product
| where unique_accounts>30
| `security_content_ctime(firstTime)`
| `security_content_ctime(lastTime)`
| `aws_multiple_users_failing_to_authenticate_from_ip_filter`
how_to_implement: You must install Splunk Add-on for AWS in order to ingest Cloudtrail. We recommend the users to try different combinations of the bucket span time and the tried account threshold to tune this search according to their environment.
known_false_positives: No known false postives for this detection. Please review this alert
references:
- https://attack.mitre.org/techniques/T1110/003/
- https://www.whiteoaksecurity.com/blog/goawsconsolespray-password-spraying-tool/
- https://softwaresecuritydotblog.wordpress.com/2019/09/28/how-to-protect-against-credential-stuffing-on-aws/
intermediate_findings:
entities:
- field: user
type: user
score: 20
message: 'Multiple failed console login attempts (Count: $unique_accounts$) against users from IP Address - $src$'
threat_objects:
- field: src
type: ip_address
analytic_story:
- AWS Identity and Access Management Account Takeover
- Compromised User Account
asset_type: AWS Account
mitre_attack_id:
- T1110.003
- T1110.004
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
category: cloud
security_domain: threat
Stages and Predicates
Stage 1: search
`cloudtrail` eventName=ConsoleLogin action=failure
Stage 2: bucket
| bucket span=10m _time
Stage 3: rename
| rename user_name as user
Stage 4: stats
| stats dc(user) AS unique_accounts values(user) as user values(user_agent) as user_agent
BY _time, src, signature,
dest, vendor_account, vendor_region,
vendor_product
Stage 5: where
| where unique_accounts>30
Stage 6: search
| `security_content_ctime(firstTime)`
Stage 7: search
| `security_content_ctime(lastTime)`
Stage 8: search
| `aws_multiple_users_failing_to_authenticate_from_ip_filter`
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
action | eq |
| field:"action" kind:eq value:"failure" |
eventName | eq |
| field:"aws::eventName" kind:eq value:"ConsoleLogin" |
sourcetype | eq |
| field:"sourcetype" kind:eq value:"aws:cloudtrail" |
unique_accounts | gt |
| field:"unique_accounts" kind:gt value:"30" |