Techniques › T1110 › T1110.004
T1110.004 Credential Stuffing
credential access — Containers, ESXi, IaaS, Identity Provider, Linux, macOS, Network Devices, Office Suite, SaaS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
9
analytics
0
Sigma rules tagged attack.t1110.004
0
KEV CVEs mapped here
<p>Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed. The information may be useful to an adversary attempting to compromise accounts by taking advantage of the tendency for users to use the same passwords across personal and business accounts.</p><p>Credential stuffing is a risky option because it could cause numerous authentication failures and account lockouts, depending on the organization's login failure policies.</p><p>Typically, management services over commonly used ports are used when stuffing credentials. Commonly targeted services include the following:</p>
- <li>SSH (22/TCP)</li><li>Telnet (23/TCP)</li><li>FTP (21/TCP)</li><li>NetBIOS / SMB / Samba (139/TCP & 445/TCP)</li><li>LDAP (389/TCP)</li><li>Kerberos (88/TCP)</li><li>RDP / Terminal Services (3389/TCP)</li><li>HTTP/HTTP Management Services (80/TCP & 443/TCP)</li><li>MSSQL (1433/TCP)</li><li>Oracle (1521/TCP)</li><li>MySQL (3306/TCP)</li><li>VNC (5900/TCP)</li>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0460 Credential Stuffing Detection via Reused Breached Credentials Across Services v1.0
AN1262 WindowsMultiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMBTunable:
UsernameUniquenessThresholdTimeWindowSourceIPScopeAN1263 LinuxRapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairsTunable:LoginFailureRatioAuthServiceFilterAN1264 macOSBurst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentialsTunable:DistinctUsernameCountRemoteAccessFilterAN1265 Identity ProviderSame source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or DuoTunable:BreachedCredentialSourceMatchSSOServiceScopeAN1266 SaaSMultiple sign-in failures against cloud-based applications using username/password combinations leaked from unrelated domainsTunable:UserAccountOverlapFailedAttemptsPerIPAN1267 Network DevicesRouter/firewall/syslog logs showing authentication failures with unique usernames and reused credentials from same source IPTunable:AuthProtocolFilterFailedAuthBurstAN1268 ContainersCredential stuffing attempts against Kubernetes API or containerized login shells using stolen or leaked user credentialsTunable:PodAccessScopeCredentialSetSizeAN1269 Office SuiteUse of leaked credential pairs against Outlook Web Access (OWA), Microsoft 365, or Exchange from a single client IP with multiple failuresTunable:PasswordSourceMatchMailboxLoginThresholdAN1270 IaaSBurst of failed login attempts across VM instances using leaked credential pairs from single IP in public cloud environmentsAWS:CloudTraileventName=ConsoleLogin | eventType=AwsConsoleSignIn→ DC0002 User Account AuthenticationTunable:InstanceIDScopeIPBehaviorHistory
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1110.004
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1110) 25
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Nasreddine Bencherchali (Nextron Systems), j4son
· 2023-10-11 (modified 2024-06-26) · logsource: product=windows service=application · 218d2855-2bba-4f61-9c85-81d0ea63ac71
Detects failed logon attempts from clients to MSSQL server.
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)
· 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 259a9cdf-c4dd-4fa2-b243-2269e5ab18a2
Detects successful logon from public IP address via RDP. This can indicate a publicly-exposed RDP port.
Author: MikeDuddington, '@dudders1'
· 2022-07-28 · logsource: product=azure service=signinlogs · 28870ae4-6a13-4616-bd1a-235a7fad7458
Detect failed authentications from countries you do not operate out of.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 28ecba0a-c743-4690-ad29-9a8f6f25a6f9
Indicates that a password spray attack has been successfully performed.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 2b7d6fc0-71ac-4cf7-8ed1-b5788ee5257a
Identifies user account which has been locked because the user tried to sign in too many times with an incorrect user ID or password.
Author: Florian Roth (Nextron Systems)
· 2022-02-25 (modified 2023-03-08) · logsource: product=windows category=process_creation · 42a993dd-bb3e-48c8-b372-4d6684c4106c
This rule detect common flag combinations used by CrackMapExec in order to detect its use even if the binary has been replaced.
Author: Tim Brown
· 2023-01-09 · logsource: product=cisco service=ldp · 50e606bf-04ce-4ca7-9d54-3449494bbd4b
Detects LDP failures which may be indicative of brute force attacks to manipulate MPLS labels
Author: Harjot Singh, '@cyb3rjy0t'
· 2023-03-20 · logsource: product=azure service=signinlogs · 53bb4f7f-48a8-4475-ac30-5a82ddfdf6fc
Detects successful authentication from potential clients using legacy authentication via user agent strings. This could be a sign of MFA bypass using a password spray attack.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-18) · logsource: product=azure service=signinlogs · 5496ff55-42ec-4369-81cb-00f417029e25
Identifies user login with multifactor authentication failures, which might be an indication an attacker has the password for the account but can't pass the MFA challenge.
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=cisco service=bgp · 56fa3cd6-f8d6-4520-a8c7-607292971886
Detects BGP failures which may be indicative of brute force attacks to manipulate routing
Author: Yochana Henderson, '@Yochana-H'
· 2022-06-17 · logsource: product=azure service=signinlogs · 60f6535a-760f-42a9-be3f-c9a0a025906e
Alert on when legacy authentication has been used on an account
Author: Ivan Saakov, Nasreddine Bencherchali
· 2025-10-19 · logsource: product=aws service=cloudtrail · 6393e346-1977-46ef-8987-ad414a145fad
Detects failed AWS console login attempts due to authentication failures. Monitoring these events is crucial for identifying potential brute-force attacks or unauthorized access attempts to AWS accounts.
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · 70ed1d26-0050-4b38-a599-92c53d57d45a
Detects user authentication failure events.
Please note that this rule can be noisy and it is recommended to use with correlation based on "author.name" field.
Author: Micah Babinski (@micahbabinski), Zach Mathis (@yamatosecurity)
· 2023-01-19 (modified 2024-03-11) · logsource: product=windows service=security · 78d5cab4-557e-454f-9fb9-a222bd0d5edc
Detects successful logon from public IP address via SMB. This can indicate a publicly-exposed SMB port.
Author: MikeDuddington, '@dudders1'
· 2022-07-28 (modified 2026-05-08) · logsource: product=azure service=signinlogs · 8c944ecb-6970-4541-8496-be554b8e2846
Detect successful authentications from countries you do not operate out of.
Author: AlertIQ
· 2021-10-10 (modified 2022-12-25) · logsource: product=azure service=signinlogs · 9a60e676-26ac-44c3-814b-0c2a8b977adf
Detect access has been blocked by Conditional Access policies.
The access policy does not allow token issuance which might be sights≈ of unauthorizeed login to valid accounts.
Author: Jerry Shockley '@jsh0x'
· 2022-02-02 · logsource: product=windows service=ntlm · 9c8acf1a-cbf9-4db6-b63c-74baabe03e59
Detects common NTLM brute force device names
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=huawei service=bgp · a557ffe6-ac54-43d2-ae69-158027082350
Detects BGP failures which may be indicative of brute force attacks to manipulate routing.
Author: Tim Brown
· 2023-01-09 (modified 2023-01-23) · logsource: product=juniper service=bgp · a7c0ae48-8df8-42bf-91bd-2ea57e2f9d43
Detects juniper BGP missing MD5 digest. Which may be indicative of brute force attacks to manipulate routing.
Author: Vasiliy Burov
· 2020-10-05 (modified 2023-02-04) · logsource: product=windows category=process_creation · aaafa146-074c-11eb-adc1-0242ac120002
Detects command line parameters used by Hydra password guessing hack tool
Author: Yochana Henderson, '@Yochana-H'
· 2022-06-01 · logsource: product=azure service=signinlogs · b4a6d707-9430-4f5f-af68-0337f52d5c42
Define a baseline threshold for failed sign-ins due to Conditional Access failures
Author: Florian Roth (Nextron Systems)
· 2017-07-08 (modified 2022-07-07) · logsource: category=proxy · c42a3073-30fb-48ae-8c99-c23ada84b103
Detects suspicious user agent strings user by hack tools in proxy logs
Author: Muhammad Faisal (@faisalusuf)
· 2024-02-25 · logsource: product=bitbucket service=audit · d3f90469-fb05-42ce-b67d-0fded91bbef3
Detects SSH user login access failures.
Please note that this rule can be noisy and is recommended to use with correlation based on "author.name" field.
Author: AlertIQ
· 2022-03-24 · logsource: product=azure service=signinlogs · e40f4962-b02b-4192-9bfe-245f7ece1f99
User has indicated they haven't instigated the MFA prompt and could indicate an attacker has the password for the account.
Author: j4son
· 2023-10-11 (modified 2025-05-28) · logsource: product=windows service=application · ebfe73c2-5bc9-4ed9-aaa8-8b54b2b4777d
Detects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.