Free kit

Free AI Tabletop Exercise Kit for SMBs

Sign up for the Cyber Defense & AI Brief and get it free.

Get the free kit

UC-L3-007

Password Spray Detection

Windows Security Event Log

Use case development / Detect Unauthorized Access / Detect Brute Force Attacks

sigma

Detection rule

title: Password Spray Attack
status: experimental
description: Detects attempts to login to many accounts with same password
logsource:
  product: windows
  service: security
detection:
  selection:
    EventID: 4625
    SubStatus: '0xC000006A'
  timeframe: 10m
  condition: selection | count(TargetUserName) by IpAddress > 20
falsepositives:
  - Misconfigured applications
level: high
tags:
  - attack.credential_access
  - attack.t1110.003

Test cases

  • Attempt login to 25 different accounts from same IP

False positive guidance

Identify and whitelist legitimate authentication sources.

ATT&CK

Detection course