Case 251F6D · Network · L5 Expert
VPN Appliance Phones Home
Practise as: Incident drill · Interview
Live alertThe vendor integrity checker on your SSL VPN appliance reports unknown files, and flow logs show it connecting to a VPS at 04:10; a public auth-bypass exploit dropped two days ago.
Interview questionYou cannot run EDR on this box. How do you investigate, contain and recover?
- 01 What happened?
- 02 What is the impact?
- 03 What do you do?
What a strong answer covers
Try it out loud first. Then check yourself:
- Treat as edge-device compromise: no EDR, on-box logs may be tampered, so rely on vendor tooling, flow and external logs
- Preserve per vendor guidance (image, logs, integrity output) before reset; then isolate or cut user and admin portals
- Assume harvested secrets: reset VPN user creds, revoke sessions, rotate the appliance LDAP/AD bind account and its certs
- Scope the pivot: hunt connections from the appliance inside IP to DCs and servers, new accounts, since the exploit date
- Rebuild from known-good firmware then patch; patching alone may not evict implants, and integrity checkers can be evaded
If the interviewer pushes back
- The integrity checker comes back clean after a reboot. Why is that not proof the device is clean?
- What architecture changes reduce the blast radius of the next edge-device zero-day?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.