Credentials & Identity

Brute Force

Repeated password or key guesses discover valid authentication material online or offline.

FoundationalWindowsLinuxSaaSWebNetwork Devices
PRIMARY MAPPINGT1110

Credential Access

01
CONCEPT

What is it?

Brute force is systematic guessing of passwords, keys, PINs, or other secrets. Online attacks submit guesses to a live service; offline attacks test guesses against stolen hashes or encrypted data without touching the target service.

02
MENTAL MODEL

How it works in plain English

Use this three-part model to understand the attack without memorizing a tool name.

01 / TRUST BEING ABUSED

The system accepts a credential, token, ticket, recovery decision, or identity assertion as proof of who the requester is.

02 / ATTACKER ACTION

The attacker obtains, guesses, forges, replays, or changes that authentication material.

03 / DEFENDER VIEW

Focus on how the identity was acquired, where it was used, what device and network context changed, and what happened immediately after success.

Worked example: how the sequence may look

01 / Starting condition

A target login, account, encrypted file, or password hash.

02 / Attacker action

Generate and submit candidate secrets.

03 / Observable evidence

Authentication failures and successes, ticket or token activity, MFA events, and account changes.

04 / Detection decision

Threshold failures by user, source, endpoint, protocol, and time.

05 / Possible outcome

If successful, the attacker may continue with Cloud Account Takeover. This is a possibility, not a guaranteed next step.

This is a defensive learning scenario. Real incidents vary, and the listed outcome is only one possible path.

03
ATTACKER OBJECTIVE

Why do attackers use it?

  • Exploit weak or predictable credentials.

  • Recover plaintext from stolen password hashes.

  • Gain access without exploiting a software vulnerability.

  • Automate account attacks at large scale.

04
REQUIRED CONDITIONS

Prerequisites

  • A target login, account, encrypted file, or password hash.

  • A candidate list or generation strategy.

  • For online attacks, reachability and tolerance for rate limiting.

  • For offline attacks, captured data and suitable compute.

05
ATTACK CHAIN

Attack path possibilities

Attack chains are not fixed. These links show common possibilities to investigate before and after this behavior.

06
SEQUENCE

Step-by-step attack flow

01

Identify the authentication target and password policy.

02

Choose online guessing, dictionary, mask, or exhaustive search.

03

Generate and submit candidate secrets.

04

Observe success or compare hashes offline.

05

Tune candidates using organization-specific words and patterns.

06

Use recovered credentials and test authorized reach.

07
FRAMEWORK

MITRE ATT&CK mapping

TECHNIQUET1110
NAMEBrute Force
TACTICCredential Access
VERIFY ON MITRE ↗

ATT&CK is updated over time. Verify the live technique before operationalizing a detection.

08
EVIDENCE

Logs and artifacts

  • Authentication failures and successes, ticket or token activity, MFA events, and account changes.

  • Identity-provider risk, device, source-network, conditional-access, and session telemetry.

  • Endpoint evidence of credential access, browser data access, or security-process interaction.

09
RAW TELEMETRY

Realistic log examples

REPRESENTATIVE, SANITIZED EXAMPLES

These records use realistic field names and formats but synthetic organizations, users, addresses, and identifiers. A single event is not proof; correlate time, identity, source, target, and the resulting action.

LOG SOURCEWindows Security — Event 4625

Failed authentication; useful for guessing, spraying, exposed remote services, and account targeting.

2026-07-16T14:22:31Z EventID=4625 Computer=DC01.corp.example
TargetUserName=j.singh TargetDomainName=CORP LogonType=3
AuthenticationPackageName=NTLM WorkstationName=WKSTN-442
IpAddress=203.0.113.48 IpPort=51842
Status=0xC000006D SubStatus=0xC000006A FailureReason="Unknown user name or bad password"
HOW TO INTERPRET IT FOR BRUTE FORCE

Threshold failures by user, source, endpoint, protocol, and time.

LOG SOURCEMicrosoft Entra — SigninLogs

Cloud sign-in context including identity, application, source, result, device, and conditional access.

2026-07-16T14:24:51Z UserPrincipalName=j.singh@corp.example
AppDisplayName="Office 365 Exchange Online" IPAddress=203.0.113.48
ResultType=50126 ResultDescription="Invalid username or password"
ClientAppUsed=Browser ConditionalAccessStatus=notApplied
DeviceDetail.operatingSystem=Windows Location=SG
HOW TO INTERPRET IT FOR BRUTE FORCE

Look for accelerating rates and systematic username/password patterns.

LOG SOURCELinux auth.log / sshd

Remote authentication and PAM outcome with source address and account.

Jul 16 14:22:33 web02 sshd[24817]: Failed password for invalid user backup
from 203.0.113.48 port 51842 ssh2
Jul 16 14:22:37 web02 sshd[24817]: Failed password for deploy
from 203.0.113.48 port 51842 ssh2
HOW TO INTERPRET IT FOR BRUTE FORCE

Correlate lockouts with sources and user agents.

READ EACH LOG WITH FIVE QUESTIONS
  1. Who or what identity acted?
  2. From which device, process, IP, or workload?
  3. What target and operation were involved?
  4. Did it fail, succeed, or change state?
  5. What correlated event happened immediately before and after?
10
ANALYTICS

Detection logic / SIEM queries

  • Threshold failures by user, source, endpoint, protocol, and time.

  • Look for accelerating rates and systematic username/password patterns.

  • Correlate lockouts with sources and user agents.

  • Alert on a success following abnormal failures.

KQLWindows failures followed by success
SecurityEvent
| where EventID in (4624, 4625)
| summarize Failures=countif(EventID == 4625),
    Successes=countif(EventID == 4624) by Account, IpAddress, bin(TimeGenerated, 15m)
| where Failures >= 20 or (Failures >= 8 and Successes > 0)
11
HARDENING

Mitigations

  • Use MFA, progressive delay, rate limiting, and smart lockout.

  • Store passwords with salted memory-hard password hashing.

  • Disable defaults and change default credentials.

  • Block common and breached passwords.

  • Restrict management interfaces to trusted networks.

12
IN THE WILD

Real-world examples

  • Internet-facing SSH and RDP are continuously targeted by automated bots.

  • The 2016 Ukraine electric power attack included scripted RPC authentication attempts.

  • Ransomware crews have brute-forced VPN, RDP, and management consoles.

13
REVIEW

Common questions

01What makes Brute Force possible?

A trust assumption fails: an identity, input, component, network message, user decision, or software relationship is accepted without enough verification.

02What should a defender collect first?

Start with logs closest to the decision point, then add identity, endpoint, network, and control-plane context.

03How should I study this attack?

Learn the concept, identify prerequisites, map observable steps, write a detection hypothesis, and validate it safely in a lab.

Primary verification sources