What MITRE ATT&CK T1110: Brute Force (Enterprise Tactic TA0006 - Credential Access) requires
MITRE ATT&CK T1110 covers adversary attempts to gain access through systematic guessing of credentials. Sub-techniques include Password Guessing (T1110.001), Password Cracking (T1110.002), Password Spraying (T1110.003), and Credential Stuffing (T1110.004). Microsoft reports approximately 4,000 password spray attacks per second against Entra ID accounts globally as of 2024. Compliance obligations include account lockout policies (NIST 800-53 AC-7), phishing-resistant MFA (NIST SP 800-63B AAL2/AAL3), and breached-credential monitoring required under PCI DSS Req 8 and ISO 27001 A.8.5.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1110/
SHA-256 integrity: 4178aeafed5a1c856d556260d34c196b4bd6e671557b5787aab8c438dea3b7f7
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1110: Brute Force (https://attack.mitre.org/techniques/T1110/) with sub-techniques for Password Guessing, Password Cracking, Password Spraying, Credential Stuffing
- NIST SP 800-63B: Digital Identity Guidelines authentication and lifecycle management
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1110-brute-force.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1110-brute-force.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1110-brute-force
- Back to registry: Browse all 10,085 compliance nodes