TACTIC: CREDENTIAL ACCESS

Brute Force (T1110): real cases

MITRE Definition ↗
Adversaries use automated credential guessing or password spraying against authentication portals.

Key Facts

Technique ID
T1110
Credential Access
Mapped Cases
3
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1110.
  • Tactical Phase: Credential Access.
  • Substantiated in 3 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Trial Transcript Day 5, Page 112
"He used automated password brute force tools to guess administrative passwords on POS point-of-sale systems."
U.S. District Court for the Western District of Washington View full case dossier →
Primary Source Evidence Excerpt: Snowflake & CrowdStrike Joint Forensic Investigation Statement
"Adversaries utilized custom automated tooling named FROSTBITE to systematically test credentials across hundreds of customer tenant URLs and generate presigned staging URLs."
U.S. Securities and Exchange Commission & FBI Cyber Division View full case dossier →
Primary Source Evidence Excerpt: Microsoft Security Response Center (MSRC) Investigation Update
"Adversaries executed a slow, distributed password spray against a non-production legacy tenant account that did not enforce multi-factor authentication."
U.S. Securities and Exchange Commission & CISA Emergency Directive 24-02 View full case dossier →