MITRE ATT&CK technique
Brute Force detection rulesT1110
Brute Force (T1110) is a MITRE ATT&CK technique in the Credential Access tactic. This page lists the 28 community-maintained Sigma detection rules in the library mapped to T1110 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, azure, bitbucket.
Tactic
External Remote SMB Logon from Public IP
highDetects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
windows
Hack Tool User Agent
highDetects suspicious user agent strings user by hack tools in proxy logs
proxy
HackTool - CrackMapExec Execution
highThis rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
windows · process_creation
HackTool - Hashcat Password Cracker Execution
highExecute Hashcat.exe with provided SAM file from registry of Windows and Password list to crack against
windows · process_creation
HackTool - Hydra Password Bruteforce Execution
highDetects command line parameters used by Hydra password guessing hack tool
windows · process_creation
Password Spray Activity
highIndicates that a password spray attack has been successfully performed.
azure
Potential MFA Bypass Using Legacy Client Authentication
highDetects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
azure
Sign-in Failure Due to Conditional Access Requirements Not Met
highDefine a baseline threshold for failed sign-ins due to Conditional Access failures
azure
Use of Legacy Authentication Protocols
highAlert on when legacy authentication has been used on an account
azure
Account Lockout
mediumIdentifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
azure
AWS ConsoleLogin Failed Authentication
mediumDetects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
aws
Bitbucket User Login Failure
mediumDetects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
bitbucket
Bitbucket User Login Failure Via SSH
mediumDetects SSH user login access failures. Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.
bitbucket
External Remote RDP Logon from Public IP
mediumDetects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
windows
MSSQL Server Failed Logon From External Network
mediumDetects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.
windows
Multifactor Authentication Denied
mediumUser has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
azure
Multifactor Authentication Interrupted
mediumIdentifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
azure
NTLM Brute Force
mediumDetects common NTLM brute force device names
windows
Successful Authentications From Countries You Do Not Operate Out Of
mediumDetect successful authentications from countries you do not operate out of.
azure
Suspicious Rejected SMB Guest Logon From IP
mediumDetect Attempt PrintNightmare (CVE-2021-1675) Remote code execution in Windows Spooler Service
windows
User Access Blocked by Azure Conditional Access
mediumDetect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
azure
Cisco BGP Authentication Failures
lowDetects BGP failures which may be indicative of brute force attacks to manipulate routing
cisco
Cisco LDP Authentication Failures
lowDetects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
cisco
Failed Authentications From Countries You Do Not Operate Out Of
lowDetect failed authentications from countries you do not operate out of.
azure
Huawei BGP Authentication Failures
lowDetects BGP failures which may be indicative of brute force attacks to manipulate routing.
huawei
Juniper BGP Missing MD5
lowDetects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
juniper
MSSQL Server Failed Logon
lowDetects failed logon attempts from clients to MSSQL server.
windows
Suspicious Connection to Remote Account
lowAdversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism
windows · ps_script