Incident response and root cause analysis after misuse of critical vulnerability on a publicly accessible server.

The organisation

A national industry organisation used a locally hosted SharePoint environment for an important planning and business process. The server was managed externally and was accessible via the Internet.

The notification

Kynexis Information Security was approached as a matter of urgency after endpoint security had reported a threat that could not be fully mitigated.

Direct incident response

Kynexis Information Security advised immediately to disconnect the Internet connection, isolate the server, change admin passwords, secure backups, replace cryptographic keys, run malware scans and activate additional logging.

The challenge is: limited forensic evidence

The environment did not have usable firewall traffic logging, active threat protection, additional Microsoft Defender logging, central Microsoft 365 logging or long-term centrally secured server logging.

The method of analysis

Kynexis Information Security combined web server logs, endpoint detection logs, server information, configuration screenshots, information from the IT service provider, open source threat intelligence and a technical root cause analysis.

The main findings

The attackers had successful access

The logging revealed that attackers had accessed through the well-known SharePoint vulnerability and had executed malicious code.

Endpoint security detected only a part

The endpoint security blocked one malicious file, but other files and communication streams remained unnoticed.

Probably approached sensitive keys.

The attack technique used was aimed at obtaining cryptographic keys and session data.

Lateral movement could not be excluded

Because network logging was missing, it could not be established whether the attackers had reached other systems.

Root cause analysis

  • an internet-oriented server with severe vulnerability;
  • late or insufficient mitigation measures;
  • expired or missing network security functionality;
  • insufficient firewall logging;
  • disabled additional layers of security;
  • limited endpoint detection;
  • insufficient demonstrable supplier control.

Summary

The investigation showed that the cyber attack was successful, malicious code was performed on the server, sensitive keys were likely approached and further compromise could not be ruled out.

The main recommendations

  • more extensive network and compromise research;
  • improving network logging;
  • activation of threat protection;
  • structural control of licences and security functions;
  • strengthening of vulnerability and patch management;
  • clearer responsibilities with the IT service provider;
  • improving incident response and forensic preparedness;
  • periodic security audits.

The result

  • a technically substantiated reconstruction;
  • confirmation that a successful breach occurred;
  • root cause analysis;
  • understanding of missing logging and detection;
  • clarification of the most likely impact;
  • recommendations for containment and follow-up research;
  • Improvement points for supplier control.

Why this approach worked

By combining web server logs, known attack techniques and configuration information, it was established that multiple malicious files had been successfully executed.

Need help with a cyber incident?

  • Incident response and digital forensic research
  • Root Cause Analyses
  • Log analysis and containment
  • Data leaks and server intrusions research
  • Incident reports for governance and management