Category: Threat Hunting
-
Hunting for VPNs in Microsoft Sentinel
Virtual Private Networks such as NordVPN, ExpressVPN, CyberGhost, Surfshark, and ProtonVPN are advertised as tools to enhance internet security. Often, VPN activity is expected from end users seeking to “improve” their privacy. Attackers will often leverage these services to launch attacks that could go undetected. Seeing an IP address from a VPN provider appears far…