I investigated anomalous NTLM logons on internal servers and traced the source addresses to devices that were not domain-joined. VPN connection records linked that internal activity to remote sessions. I checked the external source addresses against VirusTotal and AbuseIPDB, using their reputation as context for the activity visible in our logs.
I reviewed several months of VPN history and analysed the frequency of source addresses to find related access through two compromised accounts. For each identified malicious session, I followed its VPN-assigned internal address through the network logs and built a session-level account of the systems reached.
The activity included network discovery and access to a sensitive file share. We deployed Velociraptor to the hosts reached by those sessions and hunted for further abnormalities. I also identified a file-share configuration weakness that allowed unauthenticated access.
No successful privilege escalation was found in the available evidence. The investigation established the observed VPN access and the exposed share, but it did not establish where the two accounts' credentials had originally been compromised.
Closer to the work
Authentication beyond the domain
NTLM logons supplied the initial signal on internal servers. I connected their source addresses to non-domain devices and then to VPN sessions. VirusTotal and AbuseIPDB provided external-IP reputation context; the access history and network activity supplied the evidence of what those sessions did.
Open this detail ↗Historical VPN attribution
I analysed source-IP frequency across several months of VPN records, identified related activity involving two accounts, and followed VPN-assigned addresses into the network logs. Session-level network reports connected remote access with discovery activity and the file share. Velociraptor extended the investigation to the hosts reached by the identified sessions.
Open this detail ↗Observed access and unresolved entry point
The investigation found a share configuration that permitted unauthenticated access and no successful privilege escalation in the available records. The source of the VPN credentials remained unproven. The reports describe observed access; they do not establish that every attacker action was visible.
Open this detail ↗Skills established through this work