ED-104
Log/SIEM Analysis
easy

VPN Auth Spray Against Treasury Staff

Identity protection saw a burst of VPN failures from 203.0.113.44 across treasury mailboxes, then a successful logon for a.chen. Mara needs the spray-to-success chain proved in the SIEM before anyone resets half of Finance.

10-15 min40 pts

Case Brief

After the straylight-payments.com lures hit finance, identity protection flagged VPN auth failures against dc01.straylight.finance from 203.0.113.44, then a green light for a.chen@straylight.finance. Mara wants the spray pattern and the successful session bookmarked before IR starts resetting passwords in the dark.

Objective

Correlate the auth spray and the successful logon, document IOCs, and decide if this is credential compromise.

Learning Objectives

  • Show the multi-user VPN failure burst from a single external IP
  • Pin the first successful VPN session that followed the spray
  • Tie the pattern to the straylight-payments lure window without over-claiming
  • Ship the attacker IP and compromised mailbox as IOCs with a supported verdict

Topics

straylight
payment-fraud
easy