Windows Brute Force and Password Spraying Detection
Adversaries are leveraging high-volume network logon failures against Windows systems to brute force or spray credentials, often targeting multiple accounts from a single source IP.
Adversaries with no prior knowledge of legitimate system credentials frequently attempt to gain unauthorized access to Windows accounts through systematic password guessing. This activity, categorized as brute force or password spraying (T1110.001/T1110.003), involves repetitive authentication requests against target systems. Defenders observe this behavior as a rapid spike in Windows Security Event ID 4625 (Logon Failure) entries originating from a singular source IP address.
When this activity manifests, it often targets multiple distinct usernames within a very short timeframe. This threat is particularly significant for internet-facing assets or systems with exposed management interfaces such as RDP. If left undetected, successful authentication grants the adversary an initial foothold, allowing for further internal reconnaissance, privilege escalation, and exfiltration. This detection-focused brief addresses the need to monitor for high-frequency failed logon patterns while filtering out common configuration-related noise such as expired service account credentials or synchronization errors between domain controllers.
Attack Chain
- Attacker performs reconnaissance to identify network-accessible Windows hosts via scanning tools (e.g., Nmap or custom scanners).
- Attacker establishes a connection to the target Windows system using network-based protocols like RDP or SMB.
- Attacker initiates an automated script to submit consecutive authentication attempts (Logon Type 3: Network) using a wordlist of common passwords.
- Target Windows host logs these unsuccessful attempts under Security Event ID 4625, documenting the source IP, target username, and failure status code.
- Attacker iterates through multiple user accounts (Password Spraying) to maximize the probability of success while attempting to bypass account lockout thresholds.
- If a correct credential pair is guessed, the target host generates a successful logon event (Event ID 4624).
- Attacker proceeds to establish persistence, move laterally, or deploy additional malware once inside the environment.
Impact
Successful brute force or password spraying attacks lead to unauthorized account compromise, potentially providing adversaries with administrative access to the domain. This can result in large-scale data exfiltration, ransomware deployment, and lateral movement. Organizations are at risk of complete account takeover if multi-factor authentication is not strictly enforced on network-facing services.
Recommendation
- Enable Windows Audit Logon policies to capture Event ID 4625 across all endpoints.
- Deploy the provided ES|QL rule to the Elastic Stack to aggregate logon failures over 60-second windows and flag source IPs exceeding 100 failures targeting two or more accounts.
- Investigate source IPs flagged by the detection to determine if they originate from internal automation or malicious external actors.
- If the source is confirmed as malicious, isolate the affected host and implement firewall blocks for the offending IP address.
- Enforce strong authentication mechanisms and ensure all internet-exposed remote services are protected by MFA.
Immediate actions
Deploy ES|QL rule for high-frequency failed logon detection.
Threat Hunt
Identify source IPs with > 100 failed logins in 60s windows.
Data: Windows Security Event Logs (Event ID 4625)