Brute force attack on an Auth0 user
Set up the auth0 integration.
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Detect a brute force attack on a user.
Strategy
To determine a successful attempt: Detect when the same user fails to login five times and then successfully logs in. This generates a MEDIUM
severity signal.
To determine an unsuccessful attempt: Detect when the same user fails to login five times. This generates an INFO
severity signal.
Triage and response
- Inspect the logs to see if this was a valid login attempt.
- See if 2FA was authenticated
- If the user was compromised, rotate user credentials.