{"id":"T1110.004","name":"Credential Stuffing","url":"https://attack.mitre.org/techniques/T1110/004","tactics":["credential-access"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0460","stix_id":"x-mitre-detection-strategy--630ea167-088b-4958-ac19-0fc59310e262","name":"Credential Stuffing Detection via Reused Breached Credentials Across Services","url":"https://attack.mitre.org/detectionstrategies/DET0460","analytics":[{"id":"AN1262","stix_id":"x-mitre-analytic--e3e2d59b-220f-43b0-9891-7b299be27c50","name":"Analytic 1262","description":"Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1262","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"UsernameUniquenessThreshold","description":"Minimum number of unique usernames in failed login attempts before triggering alert"},{"field":"TimeWindow","description":"Duration (e.g., 5 minutes) to observe the behavior chain of rapid login attempts"},{"field":"SourceIPScope","description":"Whether to group by full IP or CIDR block for bursty behavior from botnets"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1263","stix_id":"x-mitre-analytic--95d381e5-f2d6-4164-9917-57f9b070333b","name":"Analytic 1263","description":"Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1263","platforms":["Linux"],"log_source_references":[{"name":"linux:syslog","channel":"SSH failed login","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"linux-syslog"}],"mutable_elements":[{"field":"LoginFailureRatio","description":"Ratio of failed logins per unique user attempted"},{"field":"AuthServiceFilter","description":"Restrict detection to certain protocols (e.g., sshd, login, su)"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1264","stix_id":"x-mitre-analytic--e2f104ac-b21a-4c48-8987-3e0ad73997df","name":"Analytic 1264","description":"Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1264","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"Login failure / authorization denied","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"DistinctUsernameCount","description":"Tunable threshold for number of attempted usernames in a time window"},{"field":"RemoteAccessFilter","description":"Restrict behavior detection to remote login interfaces"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1265","stix_id":"x-mitre-analytic--24e6cefb-6e1c-4676-9bb8-74f6a731703c","name":"Analytic 1265","description":"Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1265","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"status = failure","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"BreachedCredentialSourceMatch","description":"Optional enrichment using known leaked credentials database"},{"field":"SSOServiceScope","description":"Targeting only federated or hybrid identity auth flows"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1266","stix_id":"x-mitre-analytic--cfff571f-eb6b-41e2-a447-f69bc07aa77a","name":"Analytic 1266","description":"Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1266","platforms":["SaaS"],"log_source_references":[{"name":"saas-app:auth","channel":"login_failure","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"saas-app-auth"}],"mutable_elements":[{"field":"UserAccountOverlap","description":"Correlate credentials reused across multiple SaaS platforms"},{"field":"FailedAttemptsPerIP","description":"Number of failed logins from same IP before alerting"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1267","stix_id":"x-mitre-analytic--4a930e8d-75eb-469d-82d8-1e1d5764a6d4","name":"Analytic 1267","description":"Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1267","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"AAA, RADIUS, or TACACS authentication","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"AuthProtocolFilter","description":"Limit detection to interactive logins rather than SNMP/RPC"},{"field":"FailedAuthBurst","description":"Detection trigger when failure rate exceeds normal profile"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1268","stix_id":"x-mitre-analytic--23c7fff8-de08-49dd-a101-0c35ad40bd7e","name":"Analytic 1268","description":"Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1268","platforms":["Containers"],"log_source_references":[{"name":"kubernetes:apiserver","channel":"authentication.k8s.io/v1beta1","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"kubernetes-apiserver"}],"mutable_elements":[{"field":"PodAccessScope","description":"Detect attempts across multiple pods/namespaces using same IP"},{"field":"CredentialSetSize","description":"Number of username/password pairs used in attack attempt"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1269","stix_id":"x-mitre-analytic--1b3bbeab-2000-47d6-88f9-8ed519f9bed6","name":"Analytic 1269","description":"Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1269","platforms":["Office Suite"],"log_source_references":[{"name":"m365:exchange","channel":"Logon failure","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"m365-exchange"}],"mutable_elements":[{"field":"PasswordSourceMatch","description":"Optional: cross-reference to haveibeenpwned or internal credential dumps"},{"field":"MailboxLoginThreshold","description":"Tunable value for how many unique mailbox attempts trigger alert"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]},{"id":"AN1270","stix_id":"x-mitre-analytic--de41a23b-b07d-411b-80f7-d1a8f55ba459","name":"Analytic 1270","description":"Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments","url":"https://attack.mitre.org/detectionstrategies/DET0460#AN1270","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"eventName=ConsoleLogin | eventType=AwsConsoleSignIn","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"aws-cloudtrail"}],"mutable_elements":[{"field":"InstanceIDScope","description":"Define if detection should group logins per host or across cluster"},{"field":"IPBehaviorHistory","description":"Correlate against past IP reputation or behavioral profiles"}],"live":true,"detection_strategies":["DET0460"],"techniques":["T1110.004"]}],"live":true,"version":"1.0","techniques":["T1110.004"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}