Detection rules › Kusto Query Language

Failed logon attempts by valid accounts within 10 mins

Author
Microsoft Security Research
Source
upstream

'Identifies when failed logon attempts are 20 or higher during a 10 minute period (2 failed logons per minute minimum) from valid account.'

MITRE ATT&CK coverage

TacticTechniques
Credential AccessT1110 Brute Force

Event coverage

ProviderEvent IDTitle
Security-Auditing4625An account failed to log on.

Stages and Predicates

Stage 1: source

<union>

Stage 2: union

union of 2 branches

Stage 3: summarize

Stage 4: extend

Stage 5: extend