OpenCanary: MSSQL Windows Authentication Login Attempt (Logtype 9002)

Alerts on OpenCanary MSSQL events where Windows Authentication login attempts are observed.

FreeReviewedSigma · High · v5
Product
opencanary
Category
application
Author
Security Onion Solutions (SigmaHQ), DRL 1.1
Published
2024-03-08
Updated
2026-07-31
title: "OpenCanary: MSSQL Windows Authentication Login Attempt (Logtype 9002)"
id: 50d33b3f-5401-4272-acb7-fc376bd84604
status: test
description: This rule alerts when an OpenCanary node logs an MSSQL login attempt using Windows Authentication. Such attempts indicate credential access behavior consistent with adversaries probing authentication services. The detection relies on OpenCanary application telemetry where the event is identified by logtype 9002.
references:
  - https://opencanary.readthedocs.io/en/latest/starting/configuration.html#services-configuration
  - https://github.com/thinkst/opencanary/blob/a0896adfcaf0328cfd5829fe10d2878c7445138e/opencanary/logger.py#L52
  - https://github.com/SigmaHQ/sigma/blob/master/rules/application/opencanary/opencanary_mssql_login_winauth.yml
author: Security Onion Solutions, Huntrule Team
date: 2024-03-08
tags:
  - attack.credential-access
  - attack.collection
  - attack.t1003
  - attack.t1213
logsource:
  category: application
  product: opencanary
detection:
  selection:
    logtype: 9002
  condition: selection
falsepositives:
  - Unlikely
level: high
license: DRL-1.1
related:
  - id: 6e78f90f-0043-4a01-ac41-f97681613a66
    type: derived