Brute Force Investigation: How to Differentiate Between a Fault and an Attack

Brute Force investigation requires reading the full event, not just the Event ID: time, computer, user, Logon ID, Process, network source, and organizational context. The conclusion is formed by correlating several sources.
Windows and Identity investigations rely on a combination of authentication events, process creation, permission changes, Sysmon Telemetry, and organizational context. A single event rarely provides a complete conclusion. This article focuses on Brute Force investigation and is intended for beginner SOC analysts. The goal is to provide a working methodology that can be applied in practice, during professional interviews, and in a work environment, without settling for a dictionary definition.
The main challenge is that data is almost always partial. Multiple attempts against one target, rate and time, and lockout can indicate a direction, but their meaning depends on time, asset, user, and expected activity. Therefore, we will build the investigation around an investigative question, required evidence, and clear completion criteria.
The practical scenario in the article is: a decision tree for three patterns. All examples are lab data or process descriptions. When dealing with Penetration Testing, Web, or Cloud, work only with explicit authorization, a defined Scope, and the ability to stop the test.




