Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is a brute-force attack?

A brute-force attack systematically tests many possible authentication secrets until one works or the attempt is stopped.

In online account systems, that usually means repeated guesses against one or a small number of accounts.

Online and offline attacks look different

Online brute force interacts with the live service.

You may see:

  • high-volume failures;
  • regular automated timing;
  • one target account;
  • lockouts;
  • throttling;
  • changing source addresses;
  • eventual success.

Offline cracking works against copied hashes or encrypted material away from the live service.

That may leave no repeated login attempts at the service at all.

Look at the pattern, not one failure

A simple online sequence might look like:

10:00:01account admin · failed
10:00:03account admin · failed
10:00:05account admin · failed
10:00:07account admin · failed
10:00:09account admin · success

That is more informative than simply saying there were “lots of failed logins”.

Rule out routine causes

Repeated failures can also come from:

  • expired password stored in an application;
  • broken service account;
  • misconfigured scheduled task;
  • user repeatedly entering the wrong password.

Check the account, application, timing, source and operational context.

Do not overstate the final success

A successful login after repeated attempts supports the conclusion that valid authentication material was eventually accepted.

It does not automatically prove that the repeated attempts discovered the password, or who controlled the source system.

The practical point is: use volume, timing, target and outcome to distinguish brute force from ordinary authentication failure, and keep online attempts separate from offline password cracking.

Reference: CIM-049Cyber Incidents & Offender Methods