Module
Brute Force & Password Spraying in the Logs
Open the sign-in logs of a Windows domain, a Microsoft Entra tenant or a Linux SSH host after a night of failed logons and say which shape the attack took, which source it came from, which accounts it reached, and whether any password landed.
70 min · Beginner
Start Brute Force & Password Spraying in the Logs
What you will learn
- Tell a brute force, a password spray and credential stuffing apart from the same table of failures by changing what you count by
- Read an sshd auth log and close a night of brute force as noise only after checking that no failing source ever got an Accepted
- Read a Windows 4625 field by field and tell a service account with an old password from an attack
- Find a password spray in Entra sign-in logs by counting distinct accounts per source address, and say why lockout never fired
- Separate wrong passwords from right passwords stopped by MFA, find the account that signed in, and write the note that gets them reset before 09:00
Lessons
Three Shapes, One Log
Brute force, password spray and credential stuffing leave the same raw material in the log: failed logons. Only what you count by tells them apart, and the per-account rule can see one of the three.
The Noisy Front Door
An internet-facing SSH host is brute-forced every night of its life. Read sshd's one-line-per-attempt log, separate guessed names from real accounts, and run the one search that decides whether 4,212 failures are noise.
Reading a Failed Logon
A 4625 says which of ten things went wrong and from where, if you read the fields. Which computer writes it, what the domain controller writes instead, and how a locked-out backup job looks next to an attack.
The Spray Under the Threshold
761 failed sign-ins, 340 accounts, no counter above 3, no alert. Count distinct accounts by source address in the Entra sign-in log, read the error codes, and see why smart lockout and the per-account rule both stayed silent.
Failed Is Not the Same as Wrong
Conditional Access runs after the password is checked, so an MFA-required failure means the password was right. Nine of those, one sign-in on an excluded service account, and the note that gets them all handled before the business day starts.