Network & Identity Incident Response

Trace compromised VPN access into the network

I correlated NTLM logons with VPN address assignments and network activity to scope two compromised accounts, then extended host investigation with Velociraptor.

Growing MSSP with Offensive ServicesHands-on network and identity investigation2 min read

I investigated anomalous NTLM logons on internal servers and traced the source addresses to devices that were not domain-joined. VPN connection records linked that internal activity to remote sessions. I checked the external source addresses against VirusTotal and AbuseIPDB, using their reputation as context for the activity visible in our logs.

I reviewed several months of VPN history and analysed the frequency of source addresses to find related access through two compromised accounts. For each identified malicious session, I followed its VPN-assigned internal address through the network logs and built a session-level account of the systems reached.

The activity included network discovery and access to a sensitive file share. We deployed Velociraptor to the hosts reached by those sessions and hunted for further abnormalities. I also identified a file-share configuration weakness that allowed unauthenticated access.

No successful privilege escalation was found in the available evidence. The investigation established the observed VPN access and the exposed share, but it did not establish where the two accounts' credentials had originally been compromised.

Closer to the work

Authentication beyond the domain

NTLM logons supplied the initial signal on internal servers. I connected their source addresses to non-domain devices and then to VPN sessions. VirusTotal and AbuseIPDB provided external-IP reputation context; the access history and network activity supplied the evidence of what those sessions did.

Open this detail ↗
Historical VPN attribution

I analysed source-IP frequency across several months of VPN records, identified related activity involving two accounts, and followed VPN-assigned addresses into the network logs. Session-level network reports connected remote access with discovery activity and the file share. Velociraptor extended the investigation to the hosts reached by the identified sessions.

Open this detail ↗
Observed access and unresolved entry point

The investigation found a share configuration that permitted unauthenticated access and no successful privilege escalation in the available records. The source of the VPN credentials remained unproven. The reports describe observed access; they do not establish that every attacker action was visible.

Open this detail ↗

Skills established through this work

This work connects to

SOC & incident response

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.