LoFP LoFP / build servers and ci systems can sometimes trigger this alert. security test cycles that include brute force or password spraying activities may trigger this alert.

Techniques

Sample rules

Spike in Successful Logon Events from a Source IP

Description

A machine learning job found an unusually large spike in successful authentication events from a particular source IP address. This can be due to password spraying, user enumeration or brute force activity.

Detection logic

Spike in Logon Events

Description

A machine learning job found an unusually large spike in successful authentication events. This can be due to password spraying, user enumeration or brute force activity.

Detection logic