return2ozma@lemmy.world to Technology@lemmy.worldEnglish · 1 month agoMassive breach spills credentials for thousands of sensitive networksarstechnica.comexternal-linkmessage-square11linkfedilinkarrow-up1126
arrow-up1126external-linkMassive breach spills credentials for thousands of sensitive networksarstechnica.comreturn2ozma@lemmy.world to Technology@lemmy.worldEnglish · 1 month agomessage-square11linkfedilink
minus-squareBlackVenom@lemmy.worldlinkfedilinkEnglisharrow-up3·1 month agoOh they absolutely show up in logs. And if they’re half competent, this also would cause MFA prompts to users… And lockouts… So IT tickets too. Yet…
minus-squarezqps@sh.itjust.workslinkfedilinkEnglisharrow-up2·1 month agoThere’s often no MFA configured for infrastructure because teams don’t want to bother and think their own stuff is secure. What it should definitely cause is SIEM alerts.
minus-squareBlackVenom@lemmy.worldlinkfedilinkEnglisharrow-up1·21 days agoIf they aren’t doing MFA, the odds of any log monitoring, let alone siem, are near zero.
Oh they absolutely show up in logs. And if they’re half competent, this also would cause MFA prompts to users… And lockouts… So IT tickets too.
Yet…
*crickets*
There’s often no MFA configured for infrastructure because teams don’t want to bother and think their own stuff is secure.
What it should definitely cause is SIEM alerts.
If they aren’t doing MFA, the odds of any log monitoring, let alone siem, are near zero.