ED-104
Log/SIEM Analysis
easy
VPN Auth Spray Against Treasury Staff
Identity protection saw a burst of VPN failures from 203.0.113.44 across treasury mailboxes, then a successful logon for a.chen. Mara needs the spray-to-success chain proved in the SIEM before anyone resets half of Finance.
10-15 min40 pts
Case Brief
After the straylight-payments.com lures hit finance, identity protection flagged VPN auth failures against dc01.straylight.finance from 203.0.113.44, then a green light for a.chen@straylight.finance. Mara wants the spray pattern and the successful session bookmarked before IR starts resetting passwords in the dark.
Objective
Correlate the auth spray and the successful logon, document IOCs, and decide if this is credential compromise.
Learning Objectives
- Show the multi-user VPN failure burst from a single external IP
- Pin the first successful VPN session that followed the spray
- Tie the pattern to the straylight-payments lure window without over-claiming
- Ship the attacker IP and compromised mailbox as IOCs with a supported verdict
Topics
straylight
payment-fraud
easy