{"id":"T1110.003","name":"Password Spraying","url":"https://attack.mitre.org/techniques/T1110/003","tactics":["credential-access"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","Network Devices","Office Suite","SaaS","Windows","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0487","stix_id":"x-mitre-detection-strategy--84dfca59-e541-48a8-bb95-d7581a8f48d2","name":"Distributed Password Spraying via Authentication Failures Across Multiple Accounts","url":"https://attack.mitre.org/detectionstrategies/DET0487","analytics":[{"id":"AN1336","stix_id":"x-mitre-analytic--5ef73ed0-313e-4b9b-b616-8c2d02f4151a","name":"Analytic 1336","description":"A high volume of authentication failures using a single password (or small set) across many different user accounts within a defined time window","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1336","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4625, 4771, 4648","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"PasswordReuseThreshold","description":"Number of distinct accounts a password is used against before alerting"},{"field":"TimeWindow","description":"Window over which the correlation is measured (e.g., 10 mins)"},{"field":"TargetGroupFilter","description":"Limit detection to sensitive or monitored user groups (e.g., Admins)"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1337","stix_id":"x-mitre-analytic--2b751817-3de2-4388-b8b9-d43b5ecda671","name":"Analytic 1337","description":"Authentication failures across different accounts using a repeated or similar password via SSH or PAM stack within a short window","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1337","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"Failed password for invalid user","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"PasswordReusePattern","description":"Repetition or minor variation of the same password across user attempts"},{"field":"IPAggregationWindow","description":"Length of time to observe distributed spray attempts from single source"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1338","stix_id":"x-mitre-analytic--36c2c2fb-0bea-40fe-9032-c0758d381de5","name":"Analytic 1338","description":"Multiple failed login attempts across different users using common password patterns (e.g., 'Welcome2023')","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1338","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Login Window and Authd errors","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"RetryCountThreshold","description":"Total number of attempts before alerting"},{"field":"CommonPasswordList","description":"List of passwords considered suspicious due to widespread use"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1339","stix_id":"x-mitre-analytic--0527196a-1551-445c-bdd7-943dfda9b718","name":"Analytic 1339","description":"Sign-in failures across enterprise SSO applications or SaaS platforms from same IP address using the same password against multiple user identities","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1339","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Failure Reason + UserPrincipalName","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"GeoIPAnomalyCheck","description":"Use geolocation mismatches to strengthen signal"},{"field":"FailedUserRatio","description":"Proportion of total user base affected to filter noise"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1340","stix_id":"x-mitre-analytic--c35bd9de-acd9-41f9-9e4f-2a3aad461de6","name":"Analytic 1340","description":"Authentication failure logs on routers/switches showing repeated use of default or common passwords across multiple accounts","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1340","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"AAA or TACACS authentication failures","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"AuthFailureBurst","description":"Cluster of failed attempts in short period indicating spray"},{"field":"InterfaceFilter","description":"Limit detection to console/SSH vs web UI interfaces"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1341","stix_id":"x-mitre-analytic--70500794-7d3d-4538-8e88-ed6d5e998a8a","name":"Analytic 1341","description":"Repeated failed authentication attempts to container APIs, control planes, or login shells across many user names using same password","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1341","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:audit","channel":"Failed login","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"kubernetes-audit"}],"mutable_elements":[{"field":"OrchestrationScope","description":"Detect spray attempts scoped to single pod vs full cluster"},{"field":"ServiceAccountFilter","description":"Limit detection to non-service accounts to reduce noise"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1342","stix_id":"x-mitre-analytic--cfffc717-79f1-4aea-9e68-475ef52db11d","name":"Analytic 1342","description":"Failed authentication attempts across user mailboxes using identical or common passwords (e.g., OWA brute attempts)","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1342","platforms":["Office Suite"],"log_source_references":[{"name":"m365:exchange","channel":"FailedLogin","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"m365-exchange"}],"mutable_elements":[{"field":"MailboxAccessAttempts","description":"Threshold on mailbox login failures by same IP"},{"field":"EmailPatternAnalysis","description":"Match target usernames to common spray dictionaries"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]},{"id":"AN1343","stix_id":"x-mitre-analytic--c4a0d95a-2dfc-4b03-830e-d0dafca0be6f","name":"Analytic 1343","description":"SaaS applications receiving authentication failures for dozens of accounts using same password or login signature","url":"https://attack.mitre.org/detectionstrategies/DET0487#AN1343","platforms":["SaaS"],"log_source_references":[{"name":"saas:auth","channel":"signin_failed","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-auth"}],"mutable_elements":[{"field":"CloudAppScope","description":"Restrict detection to identity providers or select high-risk SaaS platforms"},{"field":"UserPopulationSensitivity","description":"Adjust based on size and role of account pool"}],"live":true,"detection_strategies":["DET0487"],"techniques":["T1110.003"]}],"live":true,"version":"1.0","techniques":["T1110.003"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}