Techniques
Sample rules
Spike in Failed Logon Events
- source: elastic
- technicques:
- T1110
Description
A machine learning job found an unusually large spike in authentication failure events. This can be due to password spraying, user enumeration or brute force activity and may be a precursor to account takeover or credentialed access.
Detection logic