Most successful network intrusions go undetected for weeks or even months. Many attackers deliberately avoid disruption during the initial stages of a compromise, preferring to quietly extract data, steal credentials, or maintain access for future use. Knowing what to look for can make the difference between detecting an incident early and discovering it only after significant damage has been done.
1. Unexpected outbound traffic
Your firewall and network logs are some of the most valuable sources of early warning. If you notice large volumes of data leaving your network at unusual times — particularly to unfamiliar IP addresses or overseas destinations — it should be treated as suspicious until proven otherwise.
Unexpected outbound traffic is often one of the earliest indicators of data exfiltration, malware command-and-control activity, or an attacker moving stolen information off-site. While many legitimate applications generate automated outbound traffic, unexplained changes in normal behaviour should always be investigated.
2. Accounts logging in at unusual times or locations
A member of staff whose account suddenly logs in at 3am, or from an unusual geographic location, should raise concern — especially if the account has elevated privileges.
We regularly see compromised Microsoft 365 accounts being used successfully for extended periods before unusual login activity is noticed. Attackers frequently rely on legitimate credentials because they attract far less attention than malware or exploit activity.
Many organisations collect authentication logs but do not routinely review them. Monitoring login times, source locations, failed login attempts, and impossible travel events can provide valuable early warning of an account compromise.
3. Disabled or modified security tools
Antivirus software being switched off, firewall rules changing unexpectedly, or endpoint protection agents suddenly stopping reporting are all strong indicators that something may be wrong.
Attackers commonly attempt to disable defensive tooling shortly after gaining access in order to avoid detection and maintain persistence. Unexpected tamper protection alerts, missing endpoint telemetry, or unauthorised Group Policy changes should always be investigated immediately.
4. New or unfamiliar user accounts
Regularly review your Active Directory, Entra ID, VPN, and local system accounts for anything unexpected or unfamiliar.
Attackers often create additional accounts or modify existing permissions to maintain long-term access to an environment. In some cases, these accounts are designed to appear legitimate by mimicking naming conventions already used within the organisation.
Privileged accounts that have not been formally authorised or documented should be treated as a priority investigation.
5. Slow or unusual system behaviour
Unexpected slowdowns, unexplained high CPU usage, unfamiliar services, or unknown scheduled tasks can all indicate malicious activity.
Cryptomining malware, for example, often becomes noticeable through degraded performance before it is formally detected. Similarly, attackers using remote access tooling or persistence mechanisms may leave behind unusual processes, PowerShell activity, or startup entries that were not previously present.
Unusual behaviour does not always indicate a cyber attack, but it should never be ignored without investigation.
What to do if you suspect a compromise
Do not panic, and avoid immediately shutting systems down unless absolutely necessary. Rebooting or powering off devices can destroy valuable forensic evidence needed to determine how the compromise occurred and what systems were affected.
Instead:
- Isolate affected systems from the network where possible
- Preserve logs before they are overwritten
- Avoid rebooting compromised devices unless advised to do so
- Record actions taken and relevant timestamps
- Contact a cyber security professional before making major changes
- Avoid using potentially compromised systems to communicate about the incident
Early detection significantly reduces the impact and cost of a security incident. Organisations that actively monitor authentication activity, endpoint telemetry, and outbound network traffic are far more likely to identify a compromise before serious damage occurs.
If you would like a professional assessment of your network’s current security posture, get in touch to discuss a vulnerability assessment or intrusion detection solution.