Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is automated credential testing?

Automated credential testing uses tools or scripts to try passwords, tokens or other authentication material against accounts or services. One controller can generate large numbers of attempts directly or distribute them through proxies and compromised devices.

Failed login volume may reveal a pattern, but it does not mean a person typed each password or that every repetition is hostile.

Describe the testing pattern precisely

Many passwords tried against one account resembles brute-force testing. A small set of passwords tried across many accounts resembles password spraying. Testing known username-and-password pairs from another source is commonly described as credential stuffing.

The pattern can be developed from:

  • target accounts and authentication routes;
  • attempted credential or token types;
  • source, device and client characteristics;
  • timing, rate and distribution;
  • success events and risk signals; and
  • tool, script or infrastructure evidence.

Misconfigured applications and devices with expired stored passwords can also generate repeated failures. Compare the rate, targets and client behaviour with legitimate system activity before classifying the sequence.

Separate testing from exploitation

A successful attempt may be handed to another system or human operator. The later session can therefore use a different address, device or client from the testing infrastructure. Link the success to subsequent activity using account, session, token and provider records, while treating the two stages separately.

Visible source addresses may belong to residential proxies, botnets or cloud providers. They describe the delivery route, not necessarily the original controller.

Key takeaway

Establish the form of automated testing, any successful authentication and the later account use as separate events; source infrastructure and repeated failures do not by themselves identify the operator.

Reference: CIM-275Cyber Incidents & Offender Methods