1200KM / simulation
T1110.001 Password Guessing — Attack Simulation
Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common…
Technique description
Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts. Without knowledge of the password for an account, an adversary may opt to systematically guess the password using a repetitive or iterative mechanism. An adversary may guess login credentials without prior knowledge of system or environment passwords during an operation by using a list of common…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Brute Force Credentials of single Active Directory domain users via SMB
Procedure 09480053-2f98-4854-be6e-71ae5f672224; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SUDO Brute Force - Redhat
Procedure 4097bc00-5eeb-4d56-aaf9-287d60351d95; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Password Brute User using Kerbrute Tool
Procedure 59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Brute Force Credentials of single Azure AD user
Procedure 5a51ef57-299e-4d62-8e11-2d440df55e69; elevation not declared required; cleanup not declared. Not executed or individually validated.
- SUDO Brute Force - FreeBSD
Procedure abcde488-e083-4ee7-bc85-a5684edd7541; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- SUDO Brute Force - Debian
Procedure ba1bf0b6-f32b-4db0-b7cc-d78cacc76700; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Brute Force Credentials of single Active Directory domain user via LDAP against domain controller (NTLM or Kerberos)
Procedure c2969434-672b-4ec8-8df0-bbb91f40e250; elevation not declared required; cleanup not declared. Not executed or individually validated.
- ESXi - Brute Force Until Account Lockout
Procedure ed6c2c87-bba6-4a28-ac6e-c8af3d6c2ab5; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.