Skip to content

Opening book details…

Can I read Detecting AD Brute Force Attacks on EtoBox?

Detecting AD Brute Force Attacks by Vilis Zhauna is a document available to read on EtoBox.

What is Detecting AD Brute Force Attacks about?

This document outlines the process for writing a Suricata rule in Security Onion to detect Active Directory password brute-force attacks, focusing on high volumes of authentication attempts over specific protocols like Kerberos, LDAP, and SMB. It provides a sample rule for detecting Kerberos authentication attempts and instructions for simulating a brute-force attack using tools like Hydra. Additionally, it suggests fine-tuning the rule by adjusting protocols, thresholds, and adding exclusions to minimize f

Author
Vilis Zhauna
Language
EN