T1110.004sub-technique of T1110 Brute Force

Credential Stuffing

Containers · ESXi · IaaS · Identity Provider · Linux · macOS · Network Devices · Office Suite · SaaS · Windowsnothing on this site yetT1110.004 on attack.mitre.org

Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap. Occasionally, large numbers of username and password pairs are dumped online when a website or service is compromised and the user account credentials accessed.

MITRE ATT&CK 19.2, retrieved 2026-09-12

If this is happening now

1

Checklists and playbooks to open while the alert is still live.

Playbook for this stage

Cloud account compromise

Impossible travel, an unrecognised inbox rule, or a reported invoice-fraud attempt.

how MITRE says to see it

Credential Stuffing Detection via Reused Breached Credentials Across Services

  • Multiple failed authentication attempts using distinct username/password pairs from a single IP address or session within a short time window, targeting common services like RDP or SMB
  • Rapid login failures across different users from a single IP address, targeting SSH or PAM login with distinct username-password pairs
  • Burst of failed authentications with rotating usernames against loginwindow or remote management service using reused breached credentials
  • Same source IP performing multiple authentication attempts using known breached username/password combinations across different identities in Azure AD, Okta, or Duo

what reduces it

  • M1027 Password Policies. Refer to NIST guidelines when creating password policies.
  • M1018 User Account Management. Proactively reset accounts that are known to be part of breached credentials either immediately, or after detecting bruteforce attempts.
  • M1032 Multi-factor Authentication. Use multi-factor authentication. Where possible, also enable multi-factor authentication on externally facing services.
  • M1036 Account Use Policies. Set account lockout policies after a certain number of failed login attempts to prevent passwords from being guessed. Too strict a policy may create a denial of service condition and render environments un-usable, with all accounts used in the brute force being locked-out. Use conditional access policies to block logins from non-compliant devices or from outside defined organization IP ranges.

the rest of T1110

The description, detection analytics and mitigations are reproduced from MITRE ATT&CK, version 19.2, under its terms of use. The checklists, hunts, labs and everything else linked here are this site’s.