{"id":"T1110","name":"Brute Force","url":"https://attack.mitre.org/techniques/T1110","tactics":["credential-access"],"platforms":["Containers","ESXi","IaaS","Identity Provider","Linux","macOS","Network Devices","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0463","stix_id":"x-mitre-detection-strategy--1439efe8-4d10-4ce8-8727-458db69bae85","name":"Brute Force Authentication Failures with Multi-Platform Log Correlation","url":"https://attack.mitre.org/detectionstrategies/DET0463","analytics":[{"id":"AN1275","stix_id":"x-mitre-analytic--db50537c-9234-4350-9bf0-838d4cffbd34","name":"Analytic 1275","description":"High volume of failed logon attempts followed by a successful one from a suspicious user, host, or timeframe","url":"https://attack.mitre.org/detectionstrategies/DET0463#AN1275","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4776, 4625","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TimeWindow","description":"Adjustable window to correlate failed logons, e.g., 5-10 minutes"},{"field":"UserContext","description":"Define scope of monitored users (e.g., service accounts, admins)"},{"field":"FailureThreshold","description":"Count of failed logons before raising an alert (e.g., 10-15)"}],"live":true,"detection_strategies":["DET0463"],"techniques":["T1110"]},{"id":"AN1276","stix_id":"x-mitre-analytic--cba73580-034b-4cdd-84a2-22704d520e9c","name":"Analytic 1276","description":"Multiple authentication failures for valid or invalid users followed by success from same IP/user","url":"https://attack.mitre.org/detectionstrategies/DET0463#AN1276","platforms":["Linux"],"log_source_references":[{"name":"auditd:USER_LOGIN","channel":"USER_AUTH","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"auditd-user-login"}],"mutable_elements":[{"field":"TimeWindow","description":"Period of brute force activity correlation (e.g., 5 mins)"},{"field":"IPWhitelist","description":"Exclude known monitoring IPs or jump boxes"},{"field":"LoginSource","description":"Filter SSH vs. local logins"}],"live":true,"detection_strategies":["DET0463"],"techniques":["T1110"]},{"id":"AN1277","stix_id":"x-mitre-analytic--72bf9819-b0b5-43ab-9c2d-195abe8165b8","name":"Analytic 1277","description":"Password spraying or brute force attempts across user pool within short time intervals","url":"https://attack.mitre.org/detectionstrategies/DET0463#AN1277","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:signinlogs","channel":"Sign-in logs","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"azure-signinlogs"}],"mutable_elements":[{"field":"UsernameSprayThreshold","description":"Max number of accounts targeted from a single IP"},{"field":"GeoAnomaly","description":"Mismatch between user location and request location"}],"live":true,"detection_strategies":["DET0463"],"techniques":["T1110"]},{"id":"AN1278","stix_id":"x-mitre-analytic--b31fc018-6fbc-4de7-9bf2-f545b5f8f0c2","name":"Analytic 1278","description":"Multiple failed authentications in unified logs (e.g., loginwindow or sshd)","url":"https://attack.mitre.org/detectionstrategies/DET0463#AN1278","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"auth","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"TimeWindow","description":"Scope of authentication failures (e.g., 10-15 mins)"},{"field":"TargetUser","description":"Filter known service or decoy accounts"}],"live":true,"detection_strategies":["DET0463"],"techniques":["T1110"]},{"id":"AN1279","stix_id":"x-mitre-analytic--a1436a64-ffc4-4e39-a7c8-140e78336ffa","name":"Analytic 1279","description":"Excessive login attempts followed by success from SaaS apps like O365, Dropbox, etc.","url":"https://attack.mitre.org/detectionstrategies/DET0463#AN1279","platforms":["SaaS"],"log_source_references":[{"name":"m365:unified","channel":"Sign-in logs","data_component":"DC0002","data_component_name":"User Account Authentication","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"AppName","description":"Detect brute force attempts targeting specific apps"},{"field":"UserGroup","description":"Limit alert scope to high-value user groups"}],"live":true,"detection_strategies":["DET0463"],"techniques":["T1110"]}],"live":true,"version":"1.0","techniques":["T1110"]}],"sigma_rules":[{"id":"218d2855-2bba-4f61-9c85-81d0ea63ac71","title":"MSSQL Server Failed Logon","author":"Nasreddine Bencherchali (Nextron Systems), j4son","status":"test","level":"low","date":"2023-10-11","modified":"2024-06-26","description":"Detects failed logon attempts from clients to MSSQL server.","references":["https://cybersecthreat.com/2020/07/08/enable-mssql-authentication-log-to-eventlog/","https://www.experts-exchange.com/questions/27800944/EventID-18456-Failed-to-open-the-explicitly-specified-database.html"],"logsource":{"product":"windows","service":"application"},"tags":["attack.credential-access","attack.t1110"],"path":"rules/windows/builtin/application/mssqlserver/win_mssql_failed_logon.yml","techniques":["T1110"],"cves":[]},{"id":"259a9cdf-c4dd-4fa2-b243-2269e5ab18a2","title":"External Remote RDP Logon from Public IP","author":"Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)","status":"test","level":"medium","date":"2023-01-19","modified":"2024-03-11","description":"Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.","references":["https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html","https://twitter.com/Purp1eW0lf/status/1616144561965002752"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1133","attack.t1078","attack.t1110"],"path":"rules/windows/builtin/security/account_management/win_security_successful_external_remote_rdp_login.yml","techniques":["T1133","T1078","T1110"],"cves":[]},{"id":"28870ae4-6a13-4616-bd1a-235a7fad7458","title":"Failed Authentications From Countries You Do Not Operate Out Of","author":"MikeDuddington, '@dudders1'","status":"test","level":"low","date":"2022-07-28","modified":null,"description":"Detect failed authentications from countries you do not operate out of.","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110"],"path":"rules-placeholder/cloud/azure/signin_logs/azure_ad_failed_auth_from_countries_you_do_not_operate_out_of.yml","techniques":["T1078.004","T1110"],"cves":[]},{"id":"28ecba0a-c743-4690-ad29-9a8f6f25a6f9","title":"Password Spray Activity","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Indicates that a password spray attack has been successfully performed.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#password-spray","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1110","attack.credential-access"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_password_spray.yml","techniques":["T1110"],"cves":[]},{"id":"2b7d6fc0-71ac-4cf7-8ed1-b5788ee5257a","title":"Account Lockout","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-25","description":"Identifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.credential-access","attack.t1110"],"path":"rules/cloud/azure/signin_logs/azure_account_lockout.yml","techniques":["T1110"],"cves":[]},{"id":"42a993dd-bb3e-48c8-b372-4d6684c4106c","title":"HackTool - CrackMapExec Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-02-25","modified":"2023-03-08","description":"This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.","references":["https://mpgn.gitbook.io/crackmapexec/smb-protocol/authentication/checking-credentials-local","https://www.mandiant.com/resources/telegram-malware-iranian-espionage","https://www.infosecmatter.com/crackmapexec-module-library/?cmem=mssql-mimikatz","https://www.infosecmatter.com/crackmapexec-module-library/?cmem=smb-pe_inject"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.discovery","attack.t1047","attack.t1053","attack.t1059.003","attack.t1059.001","attack.t1110","attack.t1201"],"path":"rules/windows/process_creation/proc_creation_win_hktl_crackmapexec_execution.yml","techniques":["T1047","T1053","T1059.003","T1059.001","T1110","T1201"],"cves":[]},{"id":"50e606bf-04ce-4ca7-9d54-3449494bbd4b","title":"Cisco LDP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":null,"description":"Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"ldp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/ldp/cisco_ldp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"53bb4f7f-48a8-4475-ac30-5a82ddfdf6fc","title":"Potential MFA Bypass Using Legacy Client Authentication","author":"Harjot Singh, '@cyb3rjy0t'","status":"test","level":"high","date":"2023-03-20","modified":null,"description":"Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.","references":["https://web.archive.org/web/20230217071802/https://blooteem.com/march-2022","https://www.microsoft.com/en-us/security/blog/2021/10/26/protect-your-business-from-password-sprays-with-microsoft-dart-recommendations/"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110"],"path":"rules/cloud/azure/signin_logs/azure_ad_suspicious_signin_bypassing_mfa.yml","techniques":["T1078.004","T1110"],"cves":[]},{"id":"5496ff55-42ec-4369-81cb-00f417029e25","title":"Multifactor Authentication Interrupted","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-18","description":"Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110","attack.t1621"],"path":"rules/cloud/azure/signin_logs/azure_mfa_interrupted.yml","techniques":["T1078.004","T1110","T1621"],"cves":[]},{"id":"56fa3cd6-f8d6-4520-a8c7-607292971886","title":"Cisco BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"cisco","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/cisco/bgp/cisco_bgp_md5_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"60f6535a-760f-42a9-be3f-c9a0a025906e","title":"Use of Legacy Authentication Protocols","author":"Yochana Henderson, '@Yochana-H'","status":"test","level":"high","date":"2022-06-17","modified":null,"description":"Alert on when legacy authentication has been used on an account","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110"],"path":"rules/cloud/azure/signin_logs/azure_legacy_authentication_protocols.yml","techniques":["T1078.004","T1110"],"cves":[]},{"id":"6393e346-1977-46ef-8987-ad414a145fad","title":"AWS ConsoleLogin Failed Authentication","author":"Ivan Saakov, Nasreddine Bencherchali","status":"experimental","level":"medium","date":"2025-10-19","modified":null,"description":"Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.\n","references":["https://naikordian.github.io/blog/posts/brute-force-aws-console/","https://help.fortinet.com/fsiem/Public_Resource_Access/7_2_1/rules/PH_RULE_AWS_Management_Console_Brute_Force_of_Root_User_Identity.htm","https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1110.001/aws_login_failure/aws_cloudtrail_events.json"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.credential-access","attack.t1110"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_console_login_failed_authentication.yml","techniques":["T1110"],"cves":[]},{"id":"70ed1d26-0050-4b38-a599-92c53d57d45a","title":"Bitbucket User Login Failure","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects user authentication failure events.\nPlease note that this rule can be noisy and it is recommended to use with correlation based on \"author.name\" field.\n","references":["https://confluence.atlassian.com/bitbucketserver/audit-log-events-776640423.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110"],"path":"rules/application/bitbucket/audit/bitbucket_audit_user_login_failure_detected.yml","techniques":["T1078.004","T1110"],"cves":[]},{"id":"78d5cab4-557e-454f-9fb9-a222bd0d5edc","title":"External Remote SMB Logon from Public IP","author":"Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)","status":"test","level":"high","date":"2023-01-19","modified":"2024-03-11","description":"Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.","references":["https://www.inversecos.com/2020/04/successful-4624-anonymous-logons-to.html","https://twitter.com/Purp1eW0lf/status/1616144561965002752"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1133","attack.t1078","attack.t1110"],"path":"rules/windows/builtin/security/account_management/win_security_successful_external_remote_smb_login.yml","techniques":["T1133","T1078","T1110"],"cves":[]},{"id":"8c944ecb-6970-4541-8496-be554b8e2846","title":"Successful Authentications From Countries You Do Not Operate Out Of","author":"MikeDuddington, '@dudders1'","status":"test","level":"medium","date":"2022-07-28","modified":"2026-05-08","description":"Detect successful authentications from countries you do not operate out of.","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-user-accounts","https://ishitasingh724.medium.com/cracking-kql-how-a-suspicious-login-alert-led-me-into-the-world-of-threat-hunting-and-the-10-kql-4ea6366ff0b3"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110"],"path":"rules-placeholder/cloud/azure/signin_logs/azure_ad_authentications_from_countries_you_do_not_operate_out_of.yml","techniques":["T1078.004","T1110"],"cves":[]},{"id":"9a60e676-26ac-44c3-814b-0c2a8b977adf","title":"User Access Blocked by Azure Conditional Access","author":"AlertIQ","status":"test","level":"medium","date":"2021-10-10","modified":"2022-12-25","description":"Detect access has been blocked by Conditional Access policies.\nThe access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.\n","references":["https://learn.microsoft.com/en-us/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.credential-access","attack.initial-access","attack.stealth","attack.t1110","attack.t1078.004"],"path":"rules/cloud/azure/signin_logs/azure_user_login_blocked_by_conditional_access.yml","techniques":["T1110","T1078.004"],"cves":[]},{"id":"9c8acf1a-cbf9-4db6-b63c-74baabe03e59","title":"NTLM Brute Force","author":"Jerry Shockley '@jsh0x'","status":"test","level":"medium","date":"2022-02-02","modified":null,"description":"Detects common NTLM brute force device names","references":["https://www.varonis.com/blog/investigate-ntlm-brute-force"],"logsource":{"product":"windows","service":"ntlm"},"tags":["attack.credential-access","attack.t1110"],"path":"rules/windows/builtin/ntlm/win_susp_ntlm_brute_force.yml","techniques":["T1110"],"cves":[]},{"id":"a557ffe6-ac54-43d2-ae69-158027082350","title":"Huawei BGP Authentication Failures","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects BGP failures which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"huawei","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/huawei/bgp/huawei_bgp_auth_failed.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43","title":"Juniper BGP Missing MD5","author":"Tim Brown","status":"test","level":"low","date":"2023-01-09","modified":"2023-01-23","description":"Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.","references":["https://www.blackhat.com/presentations/bh-usa-03/bh-us-03-convery-franz-v3.pdf"],"logsource":{"product":"juniper","service":"bgp"},"tags":["attack.initial-access","attack.persistence","attack.privilege-escalation","attack.credential-access","attack.collection","attack.stealth","attack.t1078","attack.t1110","attack.t1557"],"path":"rules/network/juniper/bgp/juniper_bgp_missing_md5.yml","techniques":["T1078","T1110","T1557"],"cves":[]},{"id":"aaafa146-074c-11eb-adc1-0242ac120002","title":"HackTool - Hydra Password Bruteforce Execution","author":"Vasiliy Burov","status":"test","level":"high","date":"2020-10-05","modified":"2023-02-04","description":"Detects command line parameters used by Hydra password guessing hack tool","references":["https://github.com/vanhauser-thc/thc-hydra"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.credential-access","attack.t1110","attack.t1110.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_hydra.yml","techniques":["T1110","T1110.001"],"cves":[]},{"id":"b4a6d707-9430-4f5f-af68-0337f52d5c42","title":"Sign-in Failure Due to Conditional Access Requirements Not Met","author":"Yochana Henderson, '@Yochana-H'","status":"test","level":"high","date":"2022-06-01","modified":null,"description":"Define a baseline threshold for failed sign-ins due to Conditional Access failures","references":["https://learn.microsoft.com/en-gb/entra/architecture/security-operations-privileged-accounts"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1110","attack.t1078.004"],"path":"rules/cloud/azure/signin_logs/azure_conditional_access_failure.yml","techniques":["T1110","T1078.004"],"cves":[]},{"id":"c42a3073-30fb-48ae-8c99-c23ada84b103","title":"Hack Tool User Agent","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-07-08","modified":"2022-07-07","description":"Detects suspicious user agent strings user by hack tools in proxy logs","references":["https://github.com/fastly/waf_testbed/blob/8bfc406551f3045e418cbaad7596cff8da331dfc/templates/default/scanners-user-agents.data.erb","http://rules.emergingthreats.net/open/snort-2.9.0/rules/emerging-user_agents.rules"],"logsource":{"category":"proxy"},"tags":["attack.initial-access","attack.t1190","attack.credential-access","attack.t1110"],"path":"rules/web/proxy_generic/proxy_ua_hacktool.yml","techniques":["T1190","T1110"],"cves":[]},{"id":"d3f90469-fb05-42ce-b67d-0fded91bbef3","title":"Bitbucket User Login Failure Via SSH","author":"Muhammad Faisal (@faisalusuf)","status":"test","level":"medium","date":"2024-02-25","modified":null,"description":"Detects SSH user login access failures.\nPlease note that this rule can be noisy and is recommended to use with correlation based on \"author.name\" field.\n","references":["https://confluence.atlassian.com/bitbucketserver/view-and-configure-the-audit-log-776640417.html","https://confluence.atlassian.com/bitbucketserver/enable-ssh-access-to-git-repositories-776640358.html"],"logsource":{"product":"bitbucket","service":"audit"},"tags":["attack.lateral-movement","attack.credential-access","attack.t1021.004","attack.t1110"],"path":"rules/application/bitbucket/audit/bitbucket_audit_user_login_failure_via_ssh_detected.yml","techniques":["T1021.004","T1110"],"cves":[]},{"id":"e40f4962-b02b-4192-9bfe-245f7ece1f99","title":"Multifactor Authentication Denied","author":"AlertIQ","status":"test","level":"medium","date":"2022-03-24","modified":null,"description":"User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.","references":["https://www.microsoft.com/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/"],"logsource":{"product":"azure","service":"signinlogs"},"tags":["attack.privilege-escalation","attack.persistence","attack.initial-access","attack.credential-access","attack.stealth","attack.t1078.004","attack.t1110","attack.t1621"],"path":"rules/cloud/azure/signin_logs/azure_mfa_denies.yml","techniques":["T1078.004","T1110","T1621"],"cves":[]},{"id":"ebfe73c2-5bc9-4ed9-aaa8-8b54b2b4777d","title":"MSSQL Server Failed Logon From External Network","author":"j4son","status":"test","level":"medium","date":"2023-10-11","modified":"2025-05-28","description":"Detects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.","references":["https://cybersecthreat.com/2020/07/08/enable-mssql-authentication-log-to-eventlog/","https://www.experts-exchange.com/questions/27800944/EventID-18456-Failed-to-open-the-explicitly-specified-database.html"],"logsource":{"product":"windows","service":"application"},"tags":["attack.credential-access","attack.t1110"],"path":"rules/windows/builtin/application/mssqlserver/win_mssql_failed_logon_from_external_network.yml","techniques":["T1110"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2020-0688","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2020-1472","state":"mapped","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}