March 11, 2024, 12:40 a.m. | /u/saadjumani

cybersecurity www.reddit.com

Hi, I recently joined a firm and we are in process of implementing SIEMs and IDPS and the very first thing we notice is that there are hundreds of login attempts coming from our solarwinds VM to our all other servers which include our email server, file server, etc.

Obviously the working theory is that the machine is compromised and whatever hacker/malware is in there is trying to expand to other systems via brute force, but since I haven't worked …

coming cybersecurity idps joined login login attempts normal notice process servers solarwinds vms

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Security Compliance Strategist

@ Grab | Petaling Jaya, Malaysia

Cloud Security Architect, Lead

@ Booz Allen Hamilton | USA, VA, McLean (1500 Tysons McLean Dr)