1200KM / detection
T1110.004 Credential Stuffing — Detection Rules
Detection workspace for T1110.004 Credential Stuffing: 0 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
T1110.004 Credential Stuffing
COUNT(authentication_failed BY source_ip, 10m) >= threshold AND DISTINCT_COUNT(account) >= threshold -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0460 Credential Stuffing Detection via Reused Breached Credentials Across Services
AN1262 Analytic 1262
Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB
AN1263 Analytic 1263
Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs
AN1264 Analytic 1264
Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials
AN1265 Analytic 1265
Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo
AN1266 Analytic 1266
Multiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domains
AN1267 Analytic 1267
Router/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IP
AN1268 Analytic 1268
Credential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentials
AN1269 Analytic 1269
Use of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failures
AN1270 Analytic 1270
Burst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environments
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1110.004 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.