Can I read Detecting AD Brute Force Attacks on EtoBox?
Detecting AD Brute Force Attacks by Vilis Zhauna is a document available to read on EtoBox.
What is Detecting AD Brute Force Attacks about?
This document outlines the process for writing a Suricata rule in Security Onion to detect Active Directory password brute-force attacks, focusing on high volumes of authentication attempts over specific protocols like Kerberos, LDAP, and SMB. It provides a sample rule for detecting Kerberos authentication attempts and instructions for simulating a brute-force attack using tools like Hydra. Additionally, it suggests fine-tuning the rule by adjusting protocols, thresholds, and adding exclusions to minimize f
- Author
- Vilis Zhauna
- Language
- EN