StealthTalk - Password brute force

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies a brute-force authentication attempt against a single StealthTalk user account. The StealthTalk anti-brute-force subsystem emits a MultiFailLogin event when consecutive failed attempts trigger an automatic account lockout. This rule fires when the reported number of consecutive failures is 9 or more, distinguishing a credential-guessing attack from an isolated user error. The lockout duration (LoginBlockingSeconds) is surfaced as a custom detail so the SOC analyst can prioritise b

Attribute Value
Type Analytic Rule
Solution StealthTalk
ID b8e5f3a2-9c4d-4d1f-8a7b-3c2d1e0f9a8b
Severity High
Status Available
Kind Scheduled
Tactics CredentialAccess, InitialAccess
Techniques T1110
Required Connectors StealthTalkAnomalousAuth
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
StealthTalkAnomalousAuth_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to StealthTalk