# Detection rule for password spraying attempts

**URL:** <https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628>\
**Category:** SIEM\
**Created:** [November 25, 2020, 9:39am UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628 "2020-11-25T09:39:37Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![heading](https://avatars.discourse-cdn.com/v4/letter/h/ecccb3/32.png) [@heading](https://discuss.elastic.co/u/heading)\
**Post date:** [November 25, 2020, 9:39am UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628/1 "2020-11-25T09:39:37Z")

</div>

Hi,

we have a use case where we want to detect if a host tries to log on to a certain number of different users. With threshold rules we are only able to detect a specific number of login attempts by a host. We cannot ensure that these login attempts are for different users, because we can only aggregate on one value.

I would appreciate ideas on how to achieve this?

---

<div class="post-metadata">

**Author:** ![spong](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spong/32/54343_2.png) [@spong](https://discuss.elastic.co/u/spong)\
**Post date:** [November 25, 2020, 11:46pm UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628/2 "2020-11-25T23:46:40Z")

</div>

Hey there @heading -- thanks for joining the community! 🙂

After chatting with some of the protections folks internally I think your best bet for this sort of detection rule (until we add support for multi-field thresholds) would be to leverage a custom ML Job + Rule.

Something like the following should do the trick, but please be sure to double check the fields to make sure they fit within your configuration (result index, time\_field/format, etc).

If not familiar with our ML functionality, you can create the job via `Machine Learning` -\> `Anomaly Detection` -\> `Create job` -\> `Select index pattern` -\> `Advanced` -\> `Edit JSON` and paste in the following for the `Job configuration JSON`:

```auto

{
  "description" : "description",
  "analysis_config" : {
    "bucket_span":"15m",
   "detectors": [
      {
        "detector_description": "high_non_zero_count by \"user.name\" partitionfield=\"host.name\"",
        "function": "high_non_zero_count",
        "by_field_name": "user.name",
        "partition_field_name": "host.name",
        "detector_index": 0
      }
    ],
    "influencers": [
      "host.name"
    ]
  },
  "results_index_name": "password-spray-host-username",
  "data_description" : {
    "time_field":"@timestamp",
    "time_format": "epoch_ms"
  }
  , "groups": ["security"]
}

```

Ensuring you provide `"groups": ["security"]` will make the job available within the Security app so you could then create a Detection Rule that would then create alerts for any anomalies greater than a specified anomaly score generated by this job.

e.g.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/1/11a6b81d258fc208053bec3f0033ec28f49cb465.png)

If you have a lot of services exposed to the open internet, and a lot of failed auth this will be a tad noisy, so you could add a numeric threshold like below which would require a large delta in the event count before producing an anomaly. More on that [here in the docs](https://www.elastic.co/guide/en/machine-learning/current/ml-configuring-detector-custom-rules.html#ml-custom-rules-conditions).

```auto
{
  "conditions": [
    {
      "applies_to": "actual",
      "operator": "lt",
      "value": 100
    }
  ]
}

```

Hopefully this is helpful and gets you moving in the right direction, but please do let us know if you have any questions. 🙂

Cheers!  
Garrett

---

<div class="post-metadata">

**Author:** ![heading](https://avatars.discourse-cdn.com/v4/letter/h/ecccb3/32.png) [@heading](https://discuss.elastic.co/u/heading)\
**Post date:** [November 26, 2020, 2:18pm UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628/3 "2020-11-26T14:18:43Z")

</div>

Thanks @spong. I'll give it a try.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 24, 2020, 2:18pm UTC](https://discuss.elastic.co/t/detection-rule-for-password-spraying-attempts/256628/4 "2020-12-24T14:18:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
