Remote access is reached without strong authentication
An internet-facing VPN or remote-access portal accepts a single factor or reused credential. Using credentials obtained earlier, the attacker connects and is placed inside the corporate network.
Get onto the internal network by authenticating to an exposed remote-access service.
- Phishing-resistant MFA on all remote access, with no exceptions
- Device-posture checks before granting network access
- Rapid patching of remote-access appliances and removal of unused ones
- VPN authentications from unusual geographies or ASNs
- Successful logins for accounts that never normally use remote access
- Concurrent sessions for one identity from different locations
- External assessment of exposed remote-access services and their auth strength
- Test whether stolen credentials alone grant network access
- Review appliance patch level and configuration
The attacker now has an internal network foothold from which to look for privilege.