Multi-CloudDetection & ResponseRetrospectives

Detecting VPN Vulnerability Exploitation: Sentinel and GuardDuty Detections

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from December 2019, written in 2026 with the benefit of hindsight.

Attackers exploiting VPN and remote access appliances often look like legitimate users. Detection focuses on suspicious sessions and what happens after them.

Signals worth watching

  • VPN logins from unusual countries, hosting providers or anonymizing services.
  • The same account connected from two locations simultaneously.
  • VPN sessions for accounts that rarely use the VPN, or disabled accounts.
  • Logins without MFA where MFA should be required.
  • Internal scanning or RDP activity originating from VPN address pools shortly after a new session.
  • Appliance logs showing unusual administrative access or configuration changes.
  • Vendor indicators of compromise published for a newly exploited vulnerability.

Where the data lives

  • VPN appliance logs forwarded to Microsoft Sentinel via Syslog/CEF connectors.
  • Entra ID sign-in logs if the VPN authenticates through Entra ID (recommended).
  • Endpoint and network telemetry for activity after connection.

A starting query

If the VPN uses Entra ID for authentication, look for VPN sign-ins from new countries per user:

SigninLogs
| where AppDisplayName has "VPN" and ResultType == "0"
| summarize Countries = make_set(Location, 10), Count = count() by UserPrincipalName, bin(TimeGenerated, 1d)
| where array_length(Countries) > 1

Response

  1. Terminate the session and disable the account temporarily.
  2. Check the appliance for known exploitation indicators and apply vendor guidance.
  3. Hunt for lateral movement from the VPN address range.
  4. Rotate credentials for accounts that used the appliance if a credential-exposing vulnerability was involved.
detect vpn vulnerability exploitationTravelex2019

More on this story