Home / Blog / Password Spray
Incident

How to Detect a Password Spray Attack?

One password, many users — different from classic brute force. SIEM correlation and Event IDs.

K
Kerem M.

Attacker in password sprayone common password(e.g. Yaz2026!) tries it on hundreds of accounts. Because the attempts per user are low, account locking will not be triggered.

symptoms

SIEM rule logic

Same source IP in 5 minute window → 10+ different usernames + failed auth = high priority alarm. at OxiSec password_spray The correlation pattern turns this chain into an incident.

Intervention

Block source IP, place affected accounts on forced password reset, enable MFA.

Analyze your logs with OxiSec

Installation in 15 minutes · community plan is free

Start Free →