09-15-2022 11:21 AM
today we have interesting alert
At least 33 distinct non-existing accounts failed to remotely log in to XX-Laptop1. Users list: name.user, user name, user.name, username
User has no idea - all day at school, behind NAT. What I cannot really understand how terminal service can be used when is user behind NAT and there is no port forwarding and any kind of redirect.
Any idea what to check next?
src. IP adresses looks ok via Virus Total
09-15-2022 12:35 PM
Ok, so the user was not behind NAT, but school Campus with /20 subnet.
Can anyone explain me, why cortex says the SRC_HOSTNAME = MSTSC.EXE? Does it makes sence?
Probably the FW is not switch to the public, so we will have to investigate the GPO.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!