GlossarySecurity awareness

Brute force attack

Short answer

A brute force attack tries large numbers of passwords or keys until one works. Variants include dictionary attacks, which use common passwords, and password spraying, which tries a few common passwords against many accounts to avoid lockouts. Exposed login pages and remote access services are the usual targets.

Variants

Pure brute force tries every possible combination and only works against short passwords. Dictionary attacks use lists of common and leaked passwords. Password spraying tries a few popular passwords, such as a season followed by the year, across many accounts so that no single account triggers a lockout. Credential stuffing uses real username and password pairs from previous breaches. Offline attacks target stolen password hashes, where attackers can try billions of guesses per second.

Common targets

Remote desktop (RDP) exposed to the internet, VPN gateways, email and cloud login pages, SSH on servers and the administration panels of web applications and network devices. Services exposed online are scanned constantly, which is why attack surface management matters.

Defences

MFA stops most online brute force attacks even when the password is guessed. Long passwords or passphrases, ideally generated by a password manager, and blocking known leaked passwords make guessing impractical. Rate limiting, temporary lockouts and alerts on many failed logins slow attackers down and reveal them. Remote access services should not be exposed directly to the internet.

Detection

Many failed logins from one source, failures spread across many accounts from the same addresses, or a success after a series of failures are typical signs. These events should be collected through log management and reviewed.

Related terms

Keep reading on this topic

Turning employees into an active line of defence: awareness training, phishing simulation, device and identity hygiene, and SaaS access control.

Go to the topic hub