Corelight
Case Study on Mitigating Identity Attacks
Pages
2
Time to read
3 mins
Publication
Language
English
Pages
2
Time to read
3 mins
Publication
Language
English
This case study details how a global financial firm effectively mitigated a sophisticated identity spoofing attack within two hours. The firm, which manages high-speed transactions and sensitive financial data, faced a challenge when attackers created unauthorized Google Workspace accounts using legitimate corporate email addresses. This method exploited existing tools and aimed to establish a trusted identity for creating rogue Slack workspaces that sent phishing links and malicious attachments. The firm's security team utilized Corelight's network evidence to connect siloed alerts and gain a comprehensive view of the attack. By analyzing DNS requests, TLS certificates, and connection logs, they identified the creation of fake accounts and correlated suspicious activities across platforms. The rapid incident response, enabled by high-fidelity evidence, allowed the team to regain control of their domain, seize fraudulent accounts, and shut down rogue workspaces, underscoring the importance of deep network visibility in combating modern identity-based threats.