Module

Brute Force & Password Spraying in the Logs

Open the sign-in logs of a Windows domain, a Microsoft Entra tenant or a Linux SSH host after a night of failed logons and say which shape the attack took, which source it came from, which accounts it reached, and whether any password landed.

70 min · Beginner

Start Brute Force & Password Spraying in the Logs

What you will learn

  • Tell a brute force, a password spray and credential stuffing apart from the same table of failures by changing what you count by
  • Read an sshd auth log and close a night of brute force as noise only after checking that no failing source ever got an Accepted
  • Read a Windows 4625 field by field and tell a service account with an old password from an attack
  • Find a password spray in Entra sign-in logs by counting distinct accounts per source address, and say why lockout never fired
  • Separate wrong passwords from right passwords stopped by MFA, find the account that signed in, and write the note that gets them reset before 09:00

Lessons

  • Three Shapes, One Log

    Brute force, password spray and credential stuffing leave the same raw material in the log: failed logons. Only what you count by tells them apart, and the per-account rule can see one of the three.

  • The Noisy Front Door

    An internet-facing SSH host is brute-forced every night of its life. Read sshd's one-line-per-attempt log, separate guessed names from real accounts, and run the one search that decides whether 4,212 failures are noise.

  • Reading a Failed Logon

    A 4625 says which of ten things went wrong and from where, if you read the fields. Which computer writes it, what the domain controller writes instead, and how a locked-out backup job looks next to an attack.

  • The Spray Under the Threshold

    761 failed sign-ins, 340 accounts, no counter above 3, no alert. Count distinct accounts by source address in the Entra sign-in log, read the error codes, and see why smart lockout and the per-account rule both stayed silent.

  • Failed Is Not the Same as Wrong

    Conditional Access runs after the password is checked, so an MFA-required failure means the password was right. Nine of those, one sign-in on an excluded service account, and the note that gets them all handled before the business day starts.

More in this zone

Brute Force & Password Spraying in the Logs | EpicDetect