I traced anomalous NTLM logons to non-domain devices and correlated their internal addresses with VPN assignment records. This connected remote sessions to server access. VirusTotal and AbuseIPDB supplied supporting IP reputation context; the session records established the link.
Viewed
Growing MSSP with Offensive Services
Connecting remote access to internal logons
Two compromised VPN accounts. One exposed file share.
Return to the full story ←