MSSQL Server Failed Logon From External Network

 Original Source: [Sigma source]
Title: MSSQL Server Failed Logon From External Network
Status: test
Description:Detects failed logon attempts from clients with external network IP to an MSSQL server. This can be a sign of a bruteforce attack.
References:
  -https://cybersecthreat.com/2020/07/08/enable-mssql-authentication-log-to-eventlog/
  -https://www.experts-exchange.com/questions/27800944/EventID-18456-Failed-to-open-the-explicitly-specified-database.html
Author: j4son
Date: 2023-10-11
modified:2025-05-28
Tags:
  • -'attack.credential-access'
  • -'attack.t1110'
Logsource:
  • product: windows
  • service: application
  • definition: Requirements: Must enable MSSQL authentication.
Detection:
  selection:
    Provider_Name|contains: 'MSSQL'
    EventID: '18456'
  filter_main_local_ips:
    Data|contains:
      -'CLIENT: 10.'
      -'CLIENT: 172.16.'
      -'CLIENT: 172.17.'
      -'CLIENT: 172.18.'
      -'CLIENT: 172.19.'
      -'CLIENT: 172.20.'
      -'CLIENT: 172.21.'
      -'CLIENT: 172.22.'
      -'CLIENT: 172.23.'
      -'CLIENT: 172.24.'
      -'CLIENT: 172.25.'
      -'CLIENT: 172.26.'
      -'CLIENT: 172.27.'
      -'CLIENT: 172.28.'
      -'CLIENT: 172.29.'
      -'CLIENT: 172.30.'
      -'CLIENT: 172.31.'
      -'CLIENT: 192.168.'
      -'CLIENT: 127.'
      -'CLIENT: 169.254.'
      -'CLIENT: <local machine>'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium