Skip to main content

Preview build: sign-in and grading run on the server. MFA is not enabled, and storage is in server memory so it does not survive a restart.

LearnDefend
Browser LabLD-SIGMA-LAB-002Medium
Browser LabLD-SIGMA-LAB-002Medium15 min

Detect Suspicious Authentication

You need a Sigma rule for password spraying (one source, many accounts, failed logons). Choose the correct logsource and the field pattern that captures the behaviour.

What you will be able to do

  • Pick the correct logsource for authentication.
  • Express the spray behaviour as a detection.
Detection EngineeringLog AnalysisT1110.003Password Spraying

Sign in to start this lab.

Sign in