NTLM logons supplied the initial signal on internal servers. I connected their source addresses to non-domain devices and then to VPN sessions. VirusTotal and AbuseIPDB provided external-IP reputation context; the access history and network activity supplied the evidence of what those sessions did.
Viewed
Growing MSSP with Offensive Services
Authentication beyond the domain
Trace compromised VPN access into the network
Return to the full story ←