Stop AD Threats As They Happen
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Control hybrid identity with policy-driven automation, secure delegation, and no scripts or standing privilege.
Unified identity resilience platform to monitor and recover across the entire Microsoft hybrid identity stack.
Track every identity change and roll back unwanted or malicious modifications.
ALWAYS FREE: Continuously detect identity threats and stop privilege abuse in real time.
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Cayosoft serves organizations across SMB to mid-enterprise industries where identity resilience, operational continuity, and hybrid Microsoft security matter most. Featured industries represent just a sample of the organizations relying on Cayosoft.
text:
Independent validation of Cayosoft’s leadership in hybrid identity management, security, and recovery across the Microsoft ecosystem.
See how enterprises and government organizations achieve identity resilience, reduce risk, and recover faster with Cayosoft.
Failed logon attempts with multiple disabled domain users might be an indication of a threat actor trying to perform a Password Spraying attack against an Active Directory environment using Kerberos to obtain initial access or elevate privileges. The detection mechanism uses the event 4768 with the failure code 0x6 stands for `client not found in Kerberos database` (the attempted user is not a valid domain user).
NOTE: This threat rule includes a built-in lookback parameter set to 25 hours. Only events that occurred within this timeframe are processed by the rule.
D3FEND: Defend Tactics
This indicates repeated failed login attempts via Kerberos, where the attempted usernames do not exist in the domain. The mechanism behind this is that an attacker is attempting to guess or crack passwords through a password spraying attack.
This is rated high severity because it indicates a potential password spraying attack, which can lead to successful login attempts and privilege escalation. The repeated failed attempts suggest an attacker is actively trying to gain access or elevate privileges in the Active Directory environment.
Attackers may use repeated failed login attempts via Kerberos to gather information about valid usernames and potentially crack passwords or gain access to the Active Directory environment through a password spraying attack. This can support later attacker activity, such as lateral movement and privilege escalation.
Cayosoft Guardian detects this by monitoring event 4768 in the Active Directory security logs, which indicates a client not found in the Kerberos database. This detection mechanism helps identify potential password spraying attacks and alerts administrators to take action.
Cayosoft Guardian reduces this risk by alerting administrators to disable or reset affected user accounts, limiting potential damage from password spraying attacks and maintaining security exposure in the Active Directory environment. This helps provide visibility into attacker activity and supports investigation and response efforts.
Cayosoft Protector provides continuous monitoring and real-time alerts across your entire Microsoft Identity stack