1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1110.004 Credential Stuffing — Detection Rules

Detection workspace for T1110.004 Credential Stuffing: 0 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

No reviewed association in this snapshot.

Atlas deterministic concepts

T1110.004 Credential Stuffing

COUNT(authentication_failed BY source_ip, 10m) >= threshold AND DISTINCT_COUNT(account) >= threshold -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0460 Credential Stuffing Detection via Reused Breached Credentials Across Services

AN1262 Analytic 1262

Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB

AN1263 Analytic 1263

Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs

AN1264 Analytic 1264

Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials

AN1265 Analytic 1265

Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo

AN1266 Analytic 1266

Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains

AN1267 Analytic 1267

Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP

AN1268 Analytic 1268

Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials

AN1269 Analytic 1269

Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures

AN1270 Analytic 1270

Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1110.004 simulation workspace

No reviewed association in this snapshot.

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.