NTConnections, a Washington DC-based MSP, responded to a SQL Server outage that turned into a full incident response. Using Huntress, they discovered attackers had brute-forced the MSSQL SA account, disabled firewall services, downloaded obfuscated backdoors via FTP, installed cryptocurrency miners, deployed antivirus-killing tools, and deleted event logs to cover their tracks. The case study outlines the attack timeline, attacker actions, and how threat hunting and remediation contained the breach before further damage occurred.
2 Impressions