Titre Mettre des comptes compromis sous surveillance
ID RA2003
Description Put (potentially) compromised accounts on monitoring
Auteur @atc_project
Creation Date 31.01.2019
Catégorie General
Étapes RS0002: Identification

Workflow

Start monitoring for authentification attempts and all potentially harmful actions from (potentially) compromised accounts.
Look for anomalies, unusual network connections, unusual geolocation/time of work, actions that were never executed before.
Keep in touch with the real users and, in case of need, ask them if they executing some suspicious actions by themselves or not.