- online to first probe
- 7 min
- online to data wiped
- 16 min
- extortion crews
- 2
- failed RDP logons
- 2,563
Honeypot and incident response
A live honeypot breach, from first probe to forensic comparison
I built a Windows and MySQL server, wrote the detections, then exposed it to the internet on purpose. Two crews wiped and ransomed the database within two hours, and a third actor guessed the admin password over RDP.
