Tag
Threat Actors Use Claude AI to Target Water Utility OT Assets
2 rules 2 TTPsAn unidentified threat actor used Claude AI to identify and target a vNode SCADA/IIoT management interface at a Mexican water utility between December 2025 and February 2026, ultimately failing to gain access.
Spike in Successful Logon Events from a Source IP
2 rules 3 TTPsA machine learning job detected a spike in successful authentication events from a source IP address, which can indicate password spraying, user enumeration, or brute force activity, potentially leading to credential access.
AWS Password Spraying Attack via Multiple Failed Console Logins
2 rules 2 TTPsA single source IP attempts to authenticate to the AWS Console against multiple unique user accounts within a short timeframe, indicating a potential password spraying attack.
Okta Password Spray Attempt Detection
2 rules 1 TTPDetection of Okta password spraying attempts by identifying multiple failed login attempts from different source IPs targeting the same user account.
Azure AD Password Spraying Attack Detection
2 rules 3 TTPsA single source IP failing to authenticate with multiple valid users in Azure AD, potentially indicating a Password Spraying attack, is detected using Azure SignInLogs and the 3-sigma rule to identify anomalous failed login patterns.
Password Spray Attack Detection via 3-Sigma Anomaly
2 rules 1 TTPThis analytic detects password spraying attacks by identifying an unusual volume of failed authentication attempts from a single source using a 3-sigma deviation from the average, leveraging the Authentication Data Model for broad CIM-mapped event coverage.
Okta ThreatInsight Detection of Credential Access Attempts
2 rules 1 TTPOkta ThreatInsight detected events indicating password spraying, login failures, and high counts of unknown user login attempts, potentially leading to unauthorized access and credential compromise.
Okta Multiple Users Failing Authentication From Single IP
2 rules 1 TTPMultiple users failing to authenticate from a single IP address within a short timeframe in Okta indicates potential brute-force or password spraying attacks, leading to unauthorized access and data breaches.
Okta Multiple Account Lockouts Indicative of Password Spraying
2 rules 1 TTPMultiple Okta accounts locked out within a 5-minute period, detected via aggregated user.account.lock events, may indicate a password spraying attack leading to potential account takeovers.
High Number of Failed Office 365 Logins from Single Source
1 rule 1 TTPThe analytic detects multiple failed login attempts in Office365 Azure Active Directory from a single source IP address, potentially indicating brute-force or password spraying attacks.
AWS High Number of Failed Console Login Attempts
2 rules 2 TTPsAn IP address exhibiting more than 20 failed AWS console login attempts within a 5-minute window, indicative of potential brute-force or password spraying attacks against AWS accounts.
AWS Console Login Password Spraying
2 rules 3 TTPsA single source IP failing to authenticate into the AWS Console with multiple valid users, potentially indicating a password spraying attack against cloud resources.
GCP Password Spraying Detection
2 rules 2 TTPsA single source IP is failing to authenticate into Google Workspace with multiple valid users, potentially indicating a Password Spraying attack.