LIVE MONITORING
Breach Help Solved

Help: Found suspicious outbound traffic to Russian IPs

By January 20, 2026 0 replies 1 views
Observer · 0 XP
January 20, 2026

Our firewall logs show consistent outbound connections from an internal server to IP ranges associated with Russian hosting providers. The traffic is encrypted and happens every 4 hours. The server is a Windows domain controller. What should our next steps be?

Best Answer
Sarah Chen
Expert · 4,800 XP
February 26, 2026

This is a potential active compromise. Treat it as an incident.

  1. DO NOT alert the attacker by blocking the IPs yet
  2. Capture a full packet capture of the traffic
  3. Image the domain controller’s memory using tools like WinPmem
  4. Check for scheduled tasks, services, and startup items that shouldn’t be there
  5. Look for Kerberoasting or Golden Ticket indicators
  6. Engage your IR team or an external firm immediately

A compromised domain controller is a worst-case scenario. The attacker likely has full domain admin access.

You must be logged in to reply.