Azure-Sentinel icon indicating copy to clipboard operation
Azure-Sentinel copied to clipboard

Password spray attack against Azure AD application

Open anfisher1967 opened this issue 4 years ago • 6 comments

It would be great if the alert for this listed the accounts that are being attacked in the entities list. Right now the only thing that shows up is the IP address which isn't very helpful. I tried to add it using Entity mapping but UserDisplayName is part of a make_set.

anfisher1967 avatar Sep 15 '21 19:09 anfisher1967

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Sep 15 '21 19:09 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Sep 21 '21 18:09 github-actions[bot]

Did this get addressed? Nothing looks different

anfisher1967 avatar Nov 16 '21 21:11 anfisher1967

Sorry for the delay on this and thanks for the suggestion. Normally in the password spray attack the same password is used on many accounts before moving on to another one and repeating the entire process again. Due to the number of possible accounts involved in a password spray it feels like it might not be optimal to map accounts to entity.

aprakash13 avatar Jan 11 '22 20:01 aprakash13

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 13:01 github-actions[bot]

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar Jan 10 '23 13:01 github-actions[bot]

Hi @anfisher1967 , thank you for flagging this. Apologies for the delayed response. If you still need assistance, please reply here within 5 business days.

v-amolpatil avatar Feb 08 '23 16:02 v-amolpatil

Nothing looks any different. Did you change anything?

anfisher1967 avatar Feb 12 '23 23:02 anfisher1967

Hi @anfisher1967, thank you for your suggestion regarding mapping accounts to entities in password spray attacks. As @aprakash13 suggested above, while this approach may work well in some cases, in the case of a password spray attack, it may not be the most optimal solution. This is because the attack involves trying the same password on many accounts before moving on to another one and repeating the process. With the number of accounts involved, mapping each account to an entity may not be the most efficient way to approach the problem. However, we appreciate your input and always welcome feedback on our processes.

v-vdixit avatar May 11 '23 12:05 v-vdixit

Gentle Reminder: We are waiting for your response on this issue. If you still need to keep this issue active, please respond on it in the next 2 days. If we don't receive response, we will be closing this issue as per our standard procedures, thanks!

v-vdixit avatar May 17 '23 12:05 v-vdixit

Since we have not received a response in the last 5 days, we are closing your issue as per our standard operating procedures. If you still need support for this issue, feel free to re-open at any time. Thank you for your co-operation.

v-vdixit avatar May 22 '23 06:05 v-vdixit

Thank you for submitting an Issue to the Azure Sentinel GitHub repo! You should expect an initial response to your Issue from the team within 5 business days. Note that this response may be delayed during holiday periods. For urgent, production-affecting issues please raise a support ticket via the Azure Portal.

github-actions[bot] avatar May 22 '23 06:05 github-actions[bot]