Variants
Pure brute force tries every possible combination and only works against short passwords. Dictionary attacks use lists of common and leaked passwords. Password spraying tries a few popular passwords, such as a season followed by the year, across many accounts so that no single account triggers a lockout. Credential stuffing uses real username and password pairs from previous breaches. Offline attacks target stolen password hashes, where attackers can try billions of guesses per second.
Common targets
Remote desktop (RDP) exposed to the internet, VPN gateways, email and cloud login pages, SSH on servers and the administration panels of web applications and network devices. Services exposed online are scanned constantly, which is why attack surface management matters.
Defences
MFA stops most online brute force attacks even when the password is guessed. Long passwords or passphrases, ideally generated by a password manager, and blocking known leaked passwords make guessing impractical. Rate limiting, temporary lockouts and alerts on many failed logins slow attackers down and reveal them. Remote access services should not be exposed directly to the internet.
Detection
Many failed logins from one source, failures spread across many accounts from the same addresses, or a success after a series of failures are typical signs. These events should be collected through log management and reviewed.




