
Summary
The Auth0 Brute Force rule is a scheduled detection mechanism that monitors login or signup attempts on the Auth0 platform. It focuses on identifying instances of brute force attacks by analyzing the rate of user authentication events. Specifically, the rule flags an incident if there are more than 10 failed login or signup attempts within a one-hour timeframe. This detection aims to mitigate the risks associated with unauthorized access attempts and protect user accounts from being compromised. The rule operates on a deduplication period of 60 minutes, ensuring that repeated alerts for the same attack vector do not overwhelm the system with notifications. This rule utilizes the specified scheduled query 'Auth0 Brute Force Detection' for operational execution.
Categories
- Cloud
- Web
- Identity Management
Data Sources
- User Account
Created: 2025-10-16