LoFP LoFP / t1110.001

t1110.001

TitleTags
a user with more than 20 failed authentication attempts in the span of 5 minutes may also be triggered by a broken application.
a user with successful authentication events from different ips may also represent the legitimate use of more than one device. filter as needed and/or customize the threshold to fit your environment.
account fallback reasons (after failed login with specific account)
administrator tooling or automated scripts may make these calls but it is highly unlikely to make several calls in a short period of time.
although unusual, users who have lost their passwords may trigger this detection. filter as needed.
software that uses the caret encased keywords pass and user in its command line
users may genuinely mistype or forget the password.