July 11, 2022, 8:27 p.m. | /u/damiandarko2

cybersecurity www.reddit.com

So we got an email from our soc1 w an alert saying that a windows server had 600 failed login attempts from an admin account on our network.

The login attempts came from an aws vm on our network that’s linked to a developer. the admin account that tried those 600 attempts is not the employee that is listed as the developer tied to the vm that tried the attempts.

basically, it’s saying that employee As workstation tried to access …

alert cybersecurity

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

SOC Cyber Threat Intelligence Expert

@ Amexio | Luxembourg, Luxembourg, Luxembourg

Systems Engineer - SecOps

@ Fortinet | Dubai, Dubai, United Arab Emirates

Ingénieur Cybersécurité Gouvernance des projets AMR H/F

@ ASSYSTEM | Lyon, France

Senior DevSecOps Consultant

@ Computacenter | Birmingham, GB, B37 7YS