Autonomous Hunter

20 IPs. Zero alerts. Invisible brute force.

0
alerts generated across 20+ attacker IPs
20+
Attacker IPs across 8+ countries
33
Failed logons via legacy WS-Trust endpoint
0
Alerts generated in SecurityAlert / AADRiskEvents
100%
Detection gap in SigninLogs

The problem

A distributed brute force campaign, completely invisible to Microsoft SigninLogs.

The Autonomous Hunter uncovered a distributed brute force campaign that ran 33 failed logons from more than 20 international IPs, completely invisible to Microsoft SigninLogs.

Legacy endpoint blind spot

OrgIdWsTrust2 is a legacy auth endpoint. Failed attempts bypass SigninLogs entirely. MFA and Conditional Access apply only after authentication, so attackers learn if a password is correct before any protection triggers. Standard SIEM rules are completely blind.

Distributed botnet TTPs

The attacker made one attempt per IP every 2 to 3 hours, rotating across India, Indonesia, Vietnam, Kenya, Egypt, Turkey, South Africa, and Europe — a classic slow distributed botnet, designed to evade rate limiting and threshold-based detection rules.

Campaign at scale

Broader scanning revealed a campaign targeting thousands of users across the org, all exploiting the same OrgIdWsTrust2 endpoint and all invisible to existing detection rules. Without behavioral anomaly detection, this runs indefinitely.

The lesson

Legacy authentication endpoints are active blind spots in every SIEM. Without behavioral anomaly detection, these attacks run indefinitely — undetected.

Contact us for a 30-day POV
on your own environment.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai