Incident report confusion
J
Jeremy Nobis
We recently received an escalation about a login through an unusual VPN service to an account at one of our clients. I wanted to share some feedback on the incident report and our follow-up with support, with the goal of helping improve reporting and user training.
When we reviewed the reported IP addresses, we recognized them as belonging to data centers we regularly block due to brute-force attempts against that same client’s VPN. We disabled the affected account, revoked all sessions, and began investigating.
Our investigation found that the attacker had successfully signed in from multiple IP addresses and registered an additional MFA method. We removed the malicious MFA method while retaining the user’s existing passkey. We also followed up with the user and verified that subsequent attempts by the attacker were failing.
The incident report described a different sequence of events. It stated that the activity was detected because of the unusual VPN, but that the attacker had removed all MFA methods and subsequent attempts were blocked because no MFA methods remained. That did not match what we observed: the attacker added an MFA method, and our team removed it while leaving the legitimate user’s passkey in place.
When we followed up with support, we were told that newly registered MFA methods are not expected to be reported and may or may not be included in the incident report.
I also want to emphasize that Huntress’s unusual VPN alert is what prompted us to investigate in the first place. That alert gave us the opportunity to identify the compromised account and take action before this became a much larger incident, and we appreciate that.
My feedback is focused on making the reporting that follows that valuable detection more accurate and useful. Clearly distinguishing the attacker’s actions from our remediation, along with explaining when newly registered MFA methods are monitored or included in reports, would help partners understand the incident and communicate it accurately to clients. This could also be a useful example for partner training: the initial alert successfully brought us into the investigation, while the differences in the final report highlight an opportunity to improve how the findings and response are documented.