Browser LabLD-SOC1-LAB-005Easy
Browser LabLD-SOC1-LAB-005Easy20 min
Password Spraying Against the Domain
Overnight, authentication failures across the domain rose from a typical 40 to just over 900. No single account was locked out, which is why nobody was paged. The morning shift has asked you to establish whether this was an attack and, if so, whether it succeeded.
What you will be able to do
- Distinguish password spraying from a classic brute-force attempt
- Determine whether any authentication succeeded
- Identify the source and recommend a proportionate response
Windows SecurityLog AnalysisIncident TriageT1110.003 — Password SprayingT1069.002 — Domain Groups
Sign in to start this lab.
Sign in