Growing MSSP with Offensive Services

Historical VPN attribution

Trace compromised VPN access into the network

I analysed source-IP frequency across several months of VPN records, identified related activity involving two accounts, and followed VPN-assigned addresses into the network logs. Session-level network reports connected remote access with discovery activity and the file share. Velociraptor extended the investigation to the hosts reached by the identified sessions.

Return to the full story ←

Your exploration

Viewed history

Saved only in this browser.

Ask my portfolio

Ask about my work.

Skills, achievements, technical detail. Follow the evidence.

Every answer links to the work.
How this works

When AI is connected, your question, recent questions and relevant published pages are sent to MiniMax to select supporting passages. Otherwise, this searches the site directly. Answers quote the saved website and link to their sources. This website does not save chat transcripts. Clearing or leaving the page clears this conversation.