ByteRay CQL Hub
← All queries

Public IP Successfully Authenticated Following Brute Force Activity

Detects account access events where CrowdStrike identified a successful login after brute force attempts originating from an internet-routable IP address.

CQL · Falcon Next-Gen SIEMCopy query
#Vendor ="crowdstrike"
|"#event_simpleName" ="RemoteBruteForceDetectInfo"
| DetectDescription=~/^A public IP successfully brute forced an account on this system/
|table([@timestamp,ComputerName,user.name,RemoteIP])
  1. Filter CrowdStrike events

Vendor ="crowdstrike"

Restricts the search to logs ingested from CrowdStrike.

  1. Filter for brute-force detection events

"#event_simpleName" ="RemoteBruteForceDetectInfo"

Returns only events generated by CrowdStrike's brute-force detection logic. These events indicate that CrowdStrike identified suspicious authentication activity consistent with a brute-force attack.

  1. Filter for successful brute-force compromises

DetectDescription=~/^A public IP successfully brute forced an account on this system/

Uses a regular expression to match detection descriptions beginning with:

A public IP successfully brute forced an account on this system

This is the most important filter because it narrows the results to cases where:

The source was a publicly routable IP address. The brute-force attack was successful. An account on the endpoint was successfully authenticated after repeated login attempts.

Public_IP_Successfully_Authenticated_Following_Brute_Force_Activity.yml
T1110.001
Kundan Kumar
Detection
Endpoint
Insight
2026-09-28
2026-09-28

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team