Overview
Pure brute force enumerates the keyspace; smart brute force starts with credential lists and mutations.\nLogin forms, SSH, FTP, database ports and panel interfaces are all common targets, and tools automate them without pause.\nDefence layers account lockout, exponential back-off, MFA and monitoring for impossible-volume failures.
Indicators of Compromise
Signals that suggest this is present on a system.
- Thousands of failures per minute from one IP
- Single account targeted across many sources
- Successful login shortly after a failure burst
Controls that stop it
-
Enforce Multi-Factor Authentication
Require a second factor on every login, and make it phishing-resistant where you can: passkeys, FIDO2 security keys or certificate-based authentication. Push-based MFA is meaningfully better than no second factor, but it is still vulnerable to fatigue and real-time relay attacks. Apply it first to remote access, email and administrative accounts.
-
Rate Limit and Monitor Authentication
Throttle failed logins per account and per source, apply exponential back-off, and alert on volumes that look like automation. Rate limit expensive endpoints such as search, password reset and OTP verification so they cannot be used for enumeration or denial of service. Logging without alerting is not monitoring.