Skip to content
CIM-050 Cyber Incidents & Offender Methods

What is an authentication attack?

An authentication attack is an attempt to defeat, bypass or misuse the process used to verify access to an account, system or service.

Avoid the dangerous assumption

The dangerous assumption is that authentication attacks only involve guessing passwords.

They may involve:

  • password spraying
  • credential stuffing
  • brute force
  • phishing
  • session theft
  • token replay
  • multi-factor fatigue
  • recovery-channel abuse
  • SIM swap
  • application-consent abuse
  • use of trusted devices
  • manipulation of single sign-on.

The method determines what evidence may exist.

Authentication logs may show attempts, results, methods, devices, applications, source infrastructure and risk assessments.

Device evidence may show browser use, malware or stolen session material.

Provider records may show recovery changes, application consent or session revocation.

Investigators should define the exact proposition.

Was there an attempt to authenticate?

Did authentication succeed?

Was the account already authenticated?

Was the access route legitimate but the user unauthorised?

Did an application act without an interactive login?

Do not assume that a successful login proves the password was known. Equally, do not assume that the absence of a login means no access occurred.

Some activity may use an existing session or token.

Keep system, account and personal attribution separate. The logs may show that a system accepted a request associated with an account or session. They may not show who personally initiated it.

Also identify legitimate explanations such as automated services, shared accounts, remote administration and recovery activity.

Operational takeaway

Identify which part of the authentication process was attacked or bypassed, and preserve the account, device, session and provider records needed to explain the access route.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.