I reviewed the available logs for root-cause analysis and to understand the attacker’s access. The incident involved access to and download of driving licences and private photographs. Connecting the access evidence with the shared management portal gave the client a clearer account of the exposure and its consequences.
Viewed
Growing MSSP with Offensive Services
Reconstruct attacker access from the logs
When training videos expose administrator credentials
Return to the full story ←