SigmaHQ/rules/linux/lnx_susp_failed_logons_single_source.yml

19 lines
552 B
YAML
Raw Normal View History

title: Multiple Failed Logins with Different Accounts from Single Source System
2017-02-16 17:02:26 +00:00
description: Detects suspicious failed logins with different user accounts from a single source system
logsource:
product: linux
service: auth
detection:
selection:
2018-03-04 21:07:01 +00:00
pam_message: "authentication failure"
pam_user: '*'
pam_rhost: '*'
timeframe: 24h
condition: selection | count(pam_user) by pam_rhost > 3
falsepositives:
- Terminal servers
- Jump servers
- Workstations with frequently changing users
2017-02-16 17:02:26 +00:00
level: medium