TI Mindmap HUB
Threat Intelligence Report

WS-Trust Autologon Endpoint: Password Spray Without Smart Lockout Blocking

📅 August 12, 2026 📰 www.varonis.com 🔍 0 CVE(s) referenced

A legacy Microsoft Entra ID endpoint allows attackers to spray passwords and confirm valid credentials—even on MFA-protected accounts—while bypassing Smart Lockout and evading standard logging, leaving organizations exposed unless legacy authentication is disabled or blocked.

unclassified

Sign in to access the full report including:
detailed analysis, IOCs, MITRE ATT&CK mapping, and STIX bundle.

🔐 Sign In to Read Full Report

You'll need to accept our Terms of Service to access the platform.

📊 Visual Mindmap
🎯 IOC Extraction
⚔️ MITRE ATT&CK TTPs
📦 STIX 2.1 Bundle