VPN Credential Stuffing and Password Spray

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Detects credential stuffing and password spray against VPN and network appliance apps registered in Entra ID, requiring a successful sign-in after the failure burst to confirm probable InitialAccess.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID a1b2c3d4-e5f6-7890-abcd-ef1234567890
Tactics InitialAccess, CredentialAccess
Techniques T1110.003, T1110.004, T1133
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AADNonInteractiveUserSignInLogs ✓ ✗ ✓
BehaviorAnalytics ✓ ✗ ✗
SigninLogs ✓ ✗ ✓
TacitRed_Findings_CL 🔶 ✗ ✓ ✗

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity