Techniques
Sample rules
Potential MFA Bypass Using Legacy Client Authentication
- source: sigma
- technicques:
- t1078
- t1078.004
- t1110
Description
Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
Detection logic
condition: selection
selection:
Status: Success
userAgent|contains:
- BAV2ROPC
- CBAinPROD
- CBAinTAR