1200KM / detection
T1110.001 Password Guessing — Detection Rules
Detection workspace for T1110.001 Password Guessing: 3 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Suspicious Rejected SMB Guest Logon From IP · test · medium · {"product":"windows","service":"smbclient-security"}
- Suspicious Connection to Remote Account · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - Hydra Password Bruteforce Execution · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1110.001 Password Guessing
COUNT(failed_authentication BY source_ip AND account, 5m) >= threshold -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0551 Password Guessing via Multi-Source Authentication Failure Correlation
AN1521 Analytic 1521
Series of authentication failures (Event ID 4625) targeting the same or similar user accounts over time from one or more remote IPs
AN1522 Analytic 1522
Repeated failed SSH login attempts followed by a possible success from the same remote host
AN1523 Analytic 1523
Series of failed logins from loginwindow or sshd with repeated usernames or password prompts
AN1524 Analytic 1524
Multiple failed sign-in attempts from external sources across many users followed by success from the same IP
AN1525 Analytic 1525
Login attempt failures over SNMP, Telnet, or SSH interface, often reflected in logs or syslog events
AN1526 Analytic 1526
Password guessing attempts against web-based apps (e.g., Dropbox, Google Workspace) reflected in API or sign-in logs
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.