{"id":"T1110.001","name":"Password Guessing","url":"https://attack.mitre.org/techniques/T1110/001","tactics":["credential-access"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0551","stix_id":"x-mitre-detection-strategy--b3ce3826-401f-4549-92ce-c825b4ddafb0","name":"Password Guessing via Multi-Source Authentication Failure Correlation","url":"https://attack.mitre.org/detectionstrategies/DET0551","analytics":[{"id":"AN1521","stix_id":"x-mitre-analytic--52dfd8de-910a-4caa-98a7-6dcf44ef903e","name":"Analytic 1521","description":"Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1521","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TimeWindow","description":"Defines the period in which multiple failed attempts are aggregated (e.g., 10 minutes)"},{"field":"UsernamePattern","description":"Filter for common account naming conventions, e.g., service accounts or administrator variants"},{"field":"SourceIPThreshold","description":"Limit on unique IPs trying to authenticate against a single account"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]},{"id":"AN1522","stix_id":"x-mitre-analytic--14390641-6cba-4351-a488-bf97c6eee8a7","name":"Analytic 1522","description":"Repeated failed SSH login attempts followed by a possible success from the same remote host","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1522","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"sshd[pid]: Failed password","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"PortScope","description":"Can be tuned to non-standard ports if SSH is moved from default"},{"field":"UserScope","description":"Filter high-value or restricted users (e.g., root, service)"},{"field":"AttemptThreshold","description":"Number of consecutive failures before flagging (e.g., >5 in 2 minutes)"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]},{"id":"AN1523","stix_id":"x-mitre-analytic--53336c8f-a218-462a-b97c-aac07cf96077","name":"Analytic 1523","description":"Series of failed logins from loginwindow or sshd with repeated usernames or password prompts","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1523","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"authd","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"AuthMechanism","description":"Local console vs. SSH vs. remote Apple Admin tools"},{"field":"FailurePattern","description":"Use regex to isolate brute force messages among other log noise"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]},{"id":"AN1524","stix_id":"x-mitre-analytic--f525a464-a4e5-40fb-831a-162af2f232e7","name":"Analytic 1524","description":"Multiple failed sign-in attempts from external sources across many users followed by success from the same IP","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1524","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Sign-in logs","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"GeoRiskScore","description":"Elevate anomalies from uncommon geolocations"},{"field":"MFAStatus","description":"Elevate logins missing MFA on high-value accounts"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]},{"id":"AN1525","stix_id":"x-mitre-analytic--13556e3f-80f0-4aac-83f0-0d6c706e76ff","name":"Analytic 1525","description":"Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1525","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"login failed","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"InterfaceType","description":"Specify monitoring of Telnet/SSH/SNMP for login activity"},{"field":"FailedAttemptThreshold","description":"How many failures in short succession should trigger alerting"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]},{"id":"AN1526","stix_id":"x-mitre-analytic--1d8bc80f-8719-41f0-a73e-127d6830f516","name":"Analytic 1526","description":"Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs","url":"https://attack.mitre.org/detectionstrategies/DET0551#AN1526","platforms":["SaaS"],"log_source_references":[{"name":"GCPAuditLogs:login.googleapis.com","channel":"Failed sign-in events","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"gcpauditlogs-login-googleapis-com"}],"mutable_elements":[{"field":"AppContext","description":"Which SaaS apps should be monitored for brute force attempts"},{"field":"EmailPattern","description":"Limit scope to enterprise domains or service accounts"}],"live":true,"detection_strategies":["DET0551"],"techniques":["T1110.001"]}],"live":true,"version":"1.0","techniques":["T1110.001"]}],"sigma_rules":[{"id":"1883444f-084b-419b-ac62-e0d0c5b3693f","title":"Suspicious Connection to Remote Account","author":"frack113","status":"test","level":"low","date":"2021-12-27","modified":null,"description":"Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.\nWithout knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1110.001/T1110.001.md#atomic-test-2---brute-force-credentials-of-single-active-directory-domain-user-via-ldap-against-domain-controller-ntlm-or-kerberos"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.credential-access","attack.t1110.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_networkcredential.yml","techniques":["T1110.001"],"cves":[]},{"id":"71886b70-d7b4-4dbf-acce-87d2ca135262","title":"Suspicious Rejected SMB Guest Logon From IP","author":"Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w","status":"test","level":"medium","date":"2021-06-30","modified":"2023-01-02","description":"Detect Attempt PrintNightmare (CVE-2021-1675) Remote code execution in Windows Spooler Service","references":["https://twitter.com/KevTheHermit/status/1410203844064301056","https://web.archive.org/web/20210629055600/https://github.com/hhlxf/PrintNightmare/","https://web.archive.org/web/20210701042336/https://github.com/afwu/PrintNightmare"],"logsource":{"product":"windows","service":"smbclient-security"},"tags":["attack.credential-access","attack.t1110.001"],"path":"rules/windows/builtin/smbclient/security/win_smbclient_security_susp_failed_guest_logon.yml","techniques":["T1110.001"],"cves":[]},{"id":"aaafa146-074c-11eb-adc1-0242ac120002","title":"HackTool - Hydra Password Bruteforce Execution","author":"Vasiliy Burov","status":"test","level":"high","date":"2020-10-05","modified":"2023-02-04","description":"Detects command line parameters used by Hydra password guessing hack tool","references":["https://github.com/vanhauser-thc/thc-hydra"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1110","attack.t1110.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_hydra.yml","techniques":["T1110","T1110.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}