Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,61 @@
# --- Query Metadata ---
# Human-readable name for the query. Will be displayed as the title.
name: "Public IP Successfully Authenticated Following Brute Force Activity"

# MITRE ATT&CK technique IDs
mitre_ids:
- "T1110.001"

# Description of what the query does and its purpose.
description: "Detects account access events where CrowdStrike identified a successful login after brute force attempts originating from an internet-routable IP address."

# The author or team that created the query.
author: "Kundan Kumar"

# The required log sources to run this query successfully in Next-Gen SIEM.
log_sources:
- Endpoint

# Tags for filtering and categorization.
tags:
- Detection

cs_required_modules:
- Insight

# --- Query Content ---
# The actual CrowdStrike Query Language (CQL) code.
cql: |
#Vendor ="crowdstrike"
|"#event_simpleName" ="RemoteBruteForceDetectInfo"
| DetectDescription=~/^A public IP successfully brute forced an account on this system/
|table([@timestamp,ComputerName,user.name,RemoteIP])

# Explanation of the query. Uses markdown for formatting on the webpage.
explanation: |
1. Filter CrowdStrike events

#Vendor ="crowdstrike"


Restricts the search to logs ingested from CrowdStrike.

2. Filter for brute-force detection events

"#event_simpleName" ="RemoteBruteForceDetectInfo"

Returns only events generated by CrowdStrike's brute-force detection logic. These events indicate that CrowdStrike identified suspicious authentication activity consistent with a brute-force attack.

3. Filter for successful brute-force compromises

DetectDescription=~/^A public IP successfully brute forced an account on this system/

Uses a regular expression to match detection descriptions beginning with:

A public IP successfully brute forced an account on this system

This is the most important filter because it narrows the results to cases where:

The source was a publicly routable IP address.
The brute-force attack was successful.
An account on the endpoint was successfully authenticated after repeated login attempts.
Loading