Edge appliance or VPN compromise

The fastest-growing intrusion route there is, and the one your normal tooling covers least. Edge devices went from a small share of exploitation-driven breaches to roughly a fifth of them in a single year, and remote access is the entry point behind the large majority of ransomware intrusions where anyone could establish one.

Trigger. A vendor advisory for a device you run at the perimeter, unexplained admin sessions on it, or an internal alert whose earliest source is the VPN range.

The first 75 minutes2 of 6 expire
038 min75
  1. 01

    Capture the device state before you touch it

    by 10 minexpires

    Support bundle, tech-support file, or whatever your vendor calls it, plus the running configuration and the session list. Do this before patching, before rebooting, and before the vendor asks you to do either. It is the only chance you get.

  2. 02

    Export the logs off the box

    by 20 minexpires

    Appliance log storage is small and circular, frequently measured in hours under load. If they are already going to a syslog collector, pull from there instead and be grateful.