Sub-technique of T1110 Brute Force.View on attack.mitre.org
Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common passwords. Password guessing may or may not take into account the target's policies on password complexity or use policies that may lock accounts out after a number of failed attempts.
Guessing passwords can be a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies.
Typically, management services over commonly used ports are used when guessing passwords. Commonly targeted services include the following:
* SSH (22/TCP)
* Telnet (23/TCP)
* FTP (21/TCP)
* NetBIOS / SMB / Samba (139/TCP & 445/TCP)
* LDAP (389/TCP)
* Kerberos (88/TCP)
* RDP / Terminal Services (3389/TCP)
* HTTP/HTTP Management Services (80/TCP & 443/TCP)
* MSSQL (1433/TCP)
* Oracle (1521/TCP)
* MySQL (3306/TCP)
* VNC (5900/TCP)
* SNMP (161/UDP and 162/TCP/UDP)
In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.. Further, adversaries may abuse network device interfaces (such as `wlanAPI`) to brute force accessible wifi-router(s) via wireless authentication protocols.
In default environments, LDAP and Kerberos connection attempts are less likely to trigger events over SMB, which creates Windows "logon failure" event ID 4625.
Rules on DetectionCode tagged with T1110.001.
| Rule | Level | Log source |
|---|---|---|
| HackTool - Hydra Password Bruteforce Execution | high | windows / process_creation |
| Suspicious Rejected SMB Guest Logon From IP | medium | windows / NULL |
| Suspicious Connection to Remote Account | low | windows / ps_script |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| ASL AWS Credential Access GetPasswordData | Anomaly | NULL | ASL AWS CloudTrail |
| AWS Credential Access Failed Login | TTP | NULL | AWS CloudTrail ConsoleLogin |
| AWS Credential Access GetPasswordData | Anomaly | NULL | AWS CloudTrail GetPasswordData |
| Azure AD High Number Of Failed Authentications For User | TTP | NULL | Azure Active Directory |
| Azure AD High Number Of Failed Authentications From Ip | TTP | NULL | Azure Active Directory |
| Azure AD Successful Authentication From Different Ips | TTP | NULL | Azure Active Directory |
| Cisco ASA - User Account Lockout Threshold Exceeded | Anomaly | NULL | Cisco ASA Logs |
| CrushFTP Max Simultaneous Users From IP | Anomaly | NULL | CrushFTP |
| High Number of Login Failures from a single source | Anomaly | NULL | O365 UserLoginFailed |
| O365 High Number Of Failed Authentications for User | TTP | NULL | O365 UserLoginFailed |
| Remote Desktop Network Bruteforce | TTP | NULL | Sysmon EventID 3 |
| Windows Remote Desktop Network Bruteforce Attempt | Anomaly | NULL | Sysmon EventID 3, Cisco Secure Access Firewall |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupAPT28 | APT28 has used a brute-force/password-spray tooling that operated in two modes: in brute-force mode it typically sent over 300 authentication attempts per hour per targeted account over the course of several hours or days. APT28 has also used a Kubernetes cluster to conduct distributed, large-scale password guessing attacks. |
| GroupAPT29 | APT29 has successfully conducted password guessing attacks against a list of mailboxes. |
| GroupVOID MANTICORE | VOID MANTICORE has conducted password guessing to gain initial access. |
| Used by | Procedure example |
|---|---|
| MalwareChina Chopper | China Chopper's server component can perform brute force password guessing against authentication portals. |
| ToolCrackMapExec | CrackMapExec can brute force passwords for a specified user on a single target system or across an entire network. |
| MalwareEmotet | Emotet has been observed using a hard coded list of passwords to brute force user accounts. |
| MalwareHermeticWizard | HermeticWizard can use a list of hardcoded credentials in attempt to authenticate to SMB shares. |
| MalwareLucifer | Lucifer has attempted to brute force TCP ports 135 (RPC) and 1433 (MSSQL) with the default username or list of usernames and passwords. |
| MalwareP.A.S. Webshell | P.A.S. Webshell can use predefined users and passwords to execute brute force attacks against SSH, FTP, POP3, MySQL, MSSQL, and PostgreSQL services. |
| MalwarePony | Pony has used a small dictionary of common passwords against a collected list of local accounts. |
| MalwareSpeakUp | SpeakUp can perform brute forcing using a pre-defined list of usernames and passwords in an attempt to log in to administrative panels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.