1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1110.003 Password Spraying — Detection Rules

Detection workspace for T1110.003 Password Spraying: 0 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

T1110.003 Password Spraying

DISTINCT_COUNT(account BY source_ip, 10m WHERE authentication_failed) >= threshold AND failures_per_account  ALERT

Anomaly models

ATT&CK analytic guidance

DET0487 Distributed Password Spraying via Authentication Failures Across Multiple Accounts

AN1336 Analytic 1336

A high volume of authentication failures using a single password (or small set) across many different user accounts within a defined time window

AN1337 Analytic 1337

Authentication failures across different accounts using a repeated or similar password via SSH or PAM stack within a short window

AN1338 Analytic 1338

Multiple failed login attempts across different users using common password patterns (e.g., 'Welcome2023')

AN1339 Analytic 1339

Sign-in failures across enterprise SSO applications or SaaS platforms from same IP address using the same password against multiple user identities

AN1340 Analytic 1340

Authentication failure logs on routers/switches showing repeated use of default or common passwords across multiple accounts

AN1341 Analytic 1341

Repeated failed authentication attempts to container APIs, control planes, or login shells across many user names using same password

AN1342 Analytic 1342

Failed authentication attempts across user mailboxes using identical or common passwords (e.g., OWA brute attempts)

AN1343 Analytic 1343

SaaS applications receiving authentication failures for dozens of accounts using same password or login signature

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1110.003 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.