• BlackVenom@lemmy.world
    link
    fedilink
    English
    arrow-up
    3
    ·
    3 days ago

    Oh they absolutely show up in logs. And if they’re half competent, this also would cause MFA prompts to users… And lockouts… So IT tickets too.

    Yet…

    • zqps@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      3 days ago

      There’s often no MFA configured for infrastructure because teams don’t want to bother and think their own stuff is secure.

      What it should definitely cause is SIEM alerts.