Public IP Successfully Authenticated Following Brute Force Activity
Detects account access events where CrowdStrike identified a successful login after brute force attempts originating from an internet-routable IP address.
#Vendor ="crowdstrike"
|"#event_simpleName" ="RemoteBruteForceDetectInfo"
| DetectDescription=~/^A public IP successfully brute forced an account on this system/
|table([@timestamp,ComputerName,user.name,RemoteIP])- Filter CrowdStrike events
Vendor ="crowdstrike"
Restricts the search to logs ingested from CrowdStrike.
- Filter for brute-force detection events
"#event_simpleName" ="RemoteBruteForceDetectInfo"
Returns only events generated by CrowdStrike's brute-force detection logic. These events indicate that CrowdStrike identified suspicious authentication activity consistent with a brute-force attack.
- Filter for successful brute-force compromises
DetectDescription=~/^A public IP successfully brute forced an account on this system/
Uses a regular expression to match detection descriptions beginning with:
A public IP successfully brute forced an account on this system
This is the most important filter because it narrows the results to cases where:
The source was a publicly routable IP address. The brute-force attack was successful. An account on the endpoint was successfully authenticated after repeated login attempts.
