Identifying a user or particular device, given the internet IP of a cellular device
内部调查发现同一人利用私人设备和可预测密码入侵云平台和本地网络账户,通过公司IP掩盖身份。时间戳和行为模式显示为同一人作案。 2025-9-26 01:18:38 Author: www.reddit.com(查看原文) 阅读量:0 收藏

How would you go about doing the above? Internal investigation, no need for court admissible evidence.

Given: A private device (cell data) has been used to break into multiple accounts with predictable passwords on a cloud platform.

Same perp has also used a device on local network to do same (similar cluster of break ins, likely same perp). Cloud side just shows my company IP, so it’s a mix of all users, but timestamp and behavior shows it’s highly likely same person, perhaps through an office owned device in this case.

I have access to WLAN controllers, routers, firewalls.

Tips, ideas?


文章来源: https://www.reddit.com/r/computerforensics/comments/1nqobz3/identifying_a_user_or_particular_device_given_the/
如有侵权请联系:admin#unsafe.sh