3 ms·
There are a few companies which are onto password spraying in this way, and use failed login attempts from a single source (e.g. IP address, ipv6 addresses with
by mpettitt 7y ago
There are a few companies which are onto password spraying in this way, and use failed login attempts from a single source (e.g. IP address, ipv6 addresses within the same allocation block, etc) as a trigger state for additional monitoring or verification. That can just mean that the soc gets a notification, or can enable captcha for suspicious sources while the attack is going on.
This does of course fail when an attacker starts using multiple sources for attack traffic. That seems to be the next step in the cat and mouse game though.