I analysed source-IP frequency across several months of VPN records, identified related activity involving two accounts, and followed VPN-assigned addresses into the network logs. Session-level network reports connected remote access with discovery activity and the file share. Velociraptor extended the investigation to the hosts reached by the identified sessions.
Viewed
Growing MSSP with Offensive Services
Historical VPN attribution
Trace compromised VPN access into the network
Return to the full story ←