Showing results for 
Show  only  | Search instead for 
Did you mean: 

Who rated this post

Cortex XDR Remote account enumeration

L2 Linker


today we have interesting alert


At least 33 distinct non-existing accounts failed to remotely log in to XX-Laptop1. Users list: name.user, user name,, username


User has no idea - all day at school, behind NAT. What I cannot really understand how terminal service can be used when is user behind NAT and there is no port forwarding and any kind of redirect.

Any idea what to check next?


src. IP adresses looks ok via Virus Total



Who rated this post