Basyrix SOC Response Atlas by Basyrix

Credential Access

T1110 — Brute Force

Adversaries may use brute force techniques — password guessing, cracking, spraying across many accounts, or credential stuffing from breached credential lists — to gain access to accounts, particularly where lockout policies are lenient, MFA is not enforced, or legacy authentication protocols are still reachable.

Correlate authentication failure volume and pattern (single account / many sources vs. many accounts / single or few sources) with any subsequent successful sign-in. Treat a success that follows a brute force or spray pattern as likely compromise until proven otherwise, regardless of whether the account itself looks privileged.

Platforms

Windows, Linux, macOS, Azure AD, Office 365, SaaS

Priority / status

high / complete

Evidence to collect

  • Target username(s)
  • Source IP(s) and ASN
  • Authentication protocol used
  • Failure count and time window
  • Any successful sign-in following failures
  • MFA challenge result, if any
  • User agent / client app