UC-L3-007
Password Spray Detection
Windows Security Event Log
Use case development / Detect Unauthorized Access / Detect Brute Force Attacks
sigma
Detection rule
title: Password Spray Attack
status: experimental
description: Detects attempts to login to many accounts with same password
logsource:
product: windows
service: security
detection:
selection:
EventID: 4625
SubStatus: '0xC000006A'
timeframe: 10m
condition: selection | count(TargetUserName) by IpAddress > 20
falsepositives:
- Misconfigured applications
level: high
tags:
- attack.credential_access
- attack.t1110.003Test cases
- Attempt login to 25 different accounts from same IP
False positive guidance
Identify and whitelist legitimate authentication sources.