Password Cracking

Last Updated At: 2025-10-15 16:09:52

Host security password cracking, based on network security defense and host intrusion detection capabilities, provides real-time monitoring of password brute force cracking behavior for the host.

Operation Guide

View Password Cracking Events

Log in to the tenant-side console of CWPP. In the left sidebar, select Intrusion Detection > Password Cracking to open the password cracking page, where you can view the password cracking event list.

Field Description:

  • Host name/Instance ID: server name and instance ID where the system has detected password cracking behavior.
  • IP address: server IP address where the system has detected password cracking behavior.
  • Source IP: attack source IP address.
  • Origin: located area of the attack source IP.
  • Protocol: the protocol used by attacker, including ssh/rdp.
  • Login username: the login username used by the attacker.
  • Port: the port used by the attacker to log in.
  • First attack time: the time when CWPP first monitors password cracking behavior.
  • Recent attack time: the most recent occurrence time of this event.
  • Number of attempts: the count statistics of the number of attempts by the attack IP to crack the password.
  • Cracking status: successful cracking, cracking failure.
  • Blocking status: blocked, unblocked.
  • Alarm status: pending processing, allowlisted, processed, ignored.
  • Operation
    • Mark as processed: If you have manually handled the alarm, you can mark the alarm as processed.
    • Add to allowlist: Create a release policy for the domain name of the current alarm. When the identical attack occurs again, the alarm will no longer execute. Meanwhile, the current alarm status will change to "allowlisted".
    • Ignore: Only ignore this alarm. If the same situation occurs again, an alarm will still be triggered.
    • Delete a record: Delete this alarm record. The console will no longer display it. Deleted records cannot be restored. Proceed with caution.

Configure the Allowlist

After the allowlist is configured, password cracking from allowlisted source IPs will not be blocked or trigger alarms. The directions are as follows:

  1. Log in to the tenant console of CWPP. In the left sidebar, select Intrusion Detection > Password Cracking. Open the password cracking page.
  2. On the password cracking page, click Allowlist Management. Enter the allowlist management page.
  3. On the allowlist management page, click Add to Allowlist. Open the allowlist creation page.
  4. In the pop-up window on the right, fill in the source IP and effective scope.

    Note:

    After adding to the allowlist, the password cracking behavior from this source IP will not be blocked or trigger alarms. Proceed with caution. If a non-allowlisted source IP attempts to log in and hits the brute force cracking rules, the system will automatically issue an exception alarm or block.

Field Description:

  • Source IP: Support filling in a single IP, IP range (such as 1.1.1.1-1.1.1.10) or IP segment (such as 1.1.1.0/24).
  • Effective scope
    • All servers (choose carefully): Add trust to the allowlist condition for all servers under user AppID.
    • Custom server range: Self-define and add the server range that trusts the allowlist condition.
  • Remarks: It is recommended that you enter relevant rule remarks.

Enable Alarm Notification

Log in to the tenant-side console of CWPP. In the left sidebar, select Settings Center > Alarm Settings. In the alarm settings, turn on the alarm notification switch. When a password cracking event occurs, you will be notified via the message center, SMS, email, WeCom, etc.

Guide for Handling Password Cracking Events

  1. When the user receives a password cracking event alarm, log in to the tenant-side console of CWPP. In the left sidebar, select Intrusion Detection > Password Cracking. Open the password cracking page.
  2. View the corresponding attack source IP in the alarm event list.
  • If it is confirmed as a trusted source IP, in the operation column on the right side of the event, the user needs to click Handle > Add to Allowlist, and set allowlist conditions and effective scope (please add to allowlist with caution). After successful configuration, it is estimated to take effect within 5 minutes. Subsequently, password cracking behavior from this source IP will no longer be alarmed or blocked.
  • If it is confirmed as an untrusted source IP, and the server password has been successfully cracked by the attacker.
    For servers that have been hacked following password cracking, you are recommended to immediately reset a complex password (a 12-16-digit complex password consisting of uppercase + lowercase + special characters + numbers) and check whether there are any unfamiliar accounts in the account list. If there are any unfamiliar accounts, delete or disable them and check for system exceptions.