VPN Credential Stuffing and Password Spray

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects credential stuffing and password spray against VPN and network appliance apps registered in Entra ID, requiring a successful sign-in after the failure burst to confirm probable InitialAccess.

Attribute Value
Type Hunting Query
Solution Hybrid Attack - Cloud & Identity
ID a1b2c3d4-e5f6-7890-abcd-ef1234567890
Tactics InitialAccess, CredentialAccess
Techniques T1110.003, T1110.004, T1133
Required Connectors AzureActiveDirectory
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AADNonInteractiveUserSignInLogs
BehaviorAnalytics ?
SigninLogs
TacitRed_Findings_CL 🔶

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Hybrid Attack - Cloud & Identity