kevmap

TechniquesT1110 › T1110.004

T1110.004 Credential Stuffing

credential access — Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
9
analytics
0
Sigma rules tagged attack.t1110.004
0
KEV CVEs mapped here
<p>Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts.</p><p>Credential stuffing is a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies.</p><p>Typically, management services over commonly used ports are used when stuffing credentials. Commonly targeted services include the following:</p>
    <li>SSH (22/TCP)</li><li>Telnet (23/TCP)</li><li>FTP (21/TCP)</li><li>NetBIOS / SMB / Samba (139/TCP & 445/TCP)</li><li>LDAP (389/TCP)</li><li>Kerberos (88/TCP)</li><li>RDP / Terminal Services (3389/TCP)</li><li>HTTP/HTTP Management Services (80/TCP & 443/TCP)</li><li>MSSQL (1433/TCP)</li><li>Oracle (1521/TCP)</li><li>MySQL (3306/TCP)</li><li>VNC (5900/TCP)</li>
<p>In addition to management services, adversaries may "target single sign-on (SSO) and cloud-based applications utilizing federated authentication protocols," as well as externally facing email applications, such as Office 365.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1110.004

No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.

Rules tagged at the parent level (attack.t1110) 25

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Nasreddine Bencherchali (Nextron Systems), j4son · 2023-10-11 (modified 2024-06-26) · logsource: product=windows service=application · 218d2855-2bba-4f61-9c85-81d0ea63ac71
Detects failed logon attempts from clients to MSSQL server.
Techniques: T1110
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity) · 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 259a9cdf-c4dd-4fa2-b243-2269e5ab18a2
Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
Techniques: T1133T1078T1110
Author: MikeDuddington, '@dudders1' · 2022-07-28 · logsource: product=azure service=signinlogs · 28870ae4-6a13-4616-bd1a-235a7fad7458
Detect failed authentications from countries you do not operate out of.
Techniques: T1078.004T1110
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo' · 2023-09-03 · logsource: product=azure service=riskdetection · 28ecba0a-c743-4690-ad29-9a8f6f25a6f9
Indicates that a password spray attack has been successfully performed.
Techniques: T1110
Account Lockout mediumtest
Author: AlertIQ · 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 2b7d6fc0-71ac-4cf7-8ed1-b5788ee5257a
Identifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
Techniques: T1110
Author: Florian Roth (Nextron Systems) · 2022-02-25 (modified 2023-03-08) · logsource: product=windows category=process_creation · 42a993dd-bb3e-48c8-b372-4d6684c4106c
This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
Author: Tim Brown · 2023-01-09 · logsource: product=cisco service=ldp · 50e606bf-04ce-4ca7-9d54-3449494bbd4b
Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
Techniques: T1078T1110T1557
Author: Harjot Singh, '@cyb3rjy0t' · 2023-03-20 · logsource: product=azure service=signinlogs · 53bb4f7f-48a8-4475-ac30-5a82ddfdf6fc
Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
Techniques: T1078.004T1110
Author: AlertIQ · 2021-10-10 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 5496ff55-42ec-4369-81cb-00f417029e25
Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=cisco service=bgp · 56fa3cd6-f8d6-4520-a8c7-607292971886
Detects BGP failures which may be indicative of brute force attacks to manipulate routing
Techniques: T1078T1110T1557
Author: Yochana Henderson, '@Yochana-H' · 2022-06-17 · logsource: product=azure service=signinlogs · 60f6535a-760f-42a9-be3f-c9a0a025906e
Alert on when legacy authentication has been used on an account
Techniques: T1078.004T1110
Author: Ivan Saakov, Nasreddine Bencherchali · 2025-10-19 · logsource: product=aws service=cloudtrail · 6393e346-1977-46ef-8987-ad414a145fad
Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
Techniques: T1110
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · 70ed1d26-0050-4b38-a599-92c53d57d45a
Detects user authentication failure events. Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
Techniques: T1078.004T1110
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity) · 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 78d5cab4-557e-454f-9fb9-a222bd0d5edc
Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
Techniques: T1133T1078T1110
Author: MikeDuddington, '@dudders1' · 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 8c944ecb-6970-4541-8496-be554b8e2846
Detect successful authentications from countries you do not operate out of.
Techniques: T1078.004T1110
Author: AlertIQ · 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 9a60e676-26ac-44c3-814b-0c2a8b977adf
Detect access has been blocked by Conditional Access policies. The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
Techniques: T1110T1078.004
NTLM Brute Force mediumtest
Author: Jerry Shockley '@jsh0x' · 2022-02-02 · logsource: product=windows service=ntlm · 9c8acf1a-cbf9-4db6-b63c-74baabe03e59
Detects common NTLM brute force device names
Techniques: T1110
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=huawei service=bgp · a557ffe6-ac54-43d2-ae69-158027082350
Detects BGP failures which may be indicative of brute force attacks to manipulate routing.
Techniques: T1078T1110T1557
Author: Tim Brown · 2023-01-09 (modified 2023-01-23) · logsource: product=juniper service=bgp · a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43
Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
Techniques: T1078T1110T1557
Author: Vasiliy Burov · 2020-10-05 (modified 2023-02-04) · logsource: product=windows category=process_creation · aaafa146-074c-11eb-adc1-0242ac120002
Detects command line parameters used by Hydra password guessing hack tool
Techniques: T1110T1110.001
Author: Yochana Henderson, '@Yochana-H' · 2022-06-01 · logsource: product=azure service=signinlogs · b4a6d707-9430-4f5f-af68-0337f52d5c42
Define a baseline threshold for failed sign-ins due to Conditional Access failures
Techniques: T1110T1078.004
Author: Florian Roth (Nextron Systems) · 2017-07-08 (modified 2022-07-07) · logsource: category=proxy · c42a3073-30fb-48ae-8c99-c23ada84b103
Detects suspicious user agent strings user by hack tools in proxy logs
Techniques: T1190T1110
Author: Muhammad Faisal (@faisalusuf) · 2024-02-25 · logsource: product=bitbucket service=audit · d3f90469-fb05-42ce-b67d-0fded91bbef3
Detects SSH user login access failures. Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.
Techniques: T1021.004T1110
Author: AlertIQ · 2022-03-24 · logsource: product=azure service=signinlogs · e40f4962-b02b-4192-9bfe-245f7ece1f99
User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
Author: j4son · 2023-10-11 (modified 2025-05-28) · logsource: product=windows service=application · ebfe73c2-5bc9-4ed9-aaa8-8b54b2b4777d
Detects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.
Techniques: T1110