Brute Force Attempt
Description
Multiple failed login attempts detected from various IP addresses targeting user account ahmed.albalushi@example.com.
Category
Source IP
192.168.1.100
Destination IP
10.0.0.5
Affected User
ahmed.albalushi@example.com
Affected System
Authentication Server
MITRE ATT&CK
Tactic: Initial Access
Technique: T1110 - Brute Force
Related Alerts
Created
3/21/2023, 10:15:00 AM
Source
Firewall
I've started investigating this case. Initial findings suggest this might be related to a compromised account.
I've checked the logs and found multiple failed login attempts from different IP addresses before the successful login.
Good catch. Let's implement a temporary block on the account and notify the user.
Review logs and identify patterns in the login attempts
Temporarily block the affected user account
Contact the user about the suspicious activity
Review and update relevant security policies