Edge appliance or VPN compromise
The fastest-growing intrusion route there is, and the one your normal tooling covers least. Edge devices went from a small share of exploitation-driven breaches to roughly a fifth of them in a single year, and remote access is the entry point behind the large majority of ransomware intrusions where anyone could establish one.
038 min75
- 01
Capture the device state before you touch it
by 10 minexpiresSupport bundle, tech-support file, or whatever your vendor calls it, plus the running configuration and the session list. Do this before patching, before rebooting, and before the vendor asks you to do either. It is the only chance you get.
- 02
Export the logs off the box
by 20 minexpiresAppliance log storage is small and circular, frequently measured in hours under load. If they are already going to a syslog collector, pull from there instead and be grateful.