Autonomous Hunter

110MB over telnet. Median is 17KB.

110MB
vs. 17KB normal median
17KB
Normal median per telnet session in the environment
110MB
First transfer, 6,000x median, Feb 24 at 16:00
100MB
Second transfer, 6,000x median, Feb 23 at 22:00
2
Ghost user's total logons ever

The problem

6,000x the normal median, off-hours, by a near-ghost user.

Two telnet sessions transferred 100+ MB each to a legacy on-premises device. 6,000x the normal median. Off-hours, by a near-ghost user with only 2 total logons ever.

What made this stand out

The volume alone would be enough to flag. But it showed up off-hours, both times on a Tuesday, on a device with no process or file event monitoring. The user behind it had logged on twice, ever. And the device itself was a dark spot in the network: legacy, on-prem, no Azure presence, nothing but telnet.

Beyond SIEM blind spots

No endpoint agent covered this device, no Azure telemetry existed for it, and nothing was logging its processes. Traditional security tools had no way to see it. Only network-level anomaly detection on raw traffic metadata could have caught this, and only because a baseline for normal behavior already existed to compare against.

What happened next

No one knew what this device was, who was using it, or why 200MB moved over telnet off hours. It required immediate investigation.

Contact us for a 30-day POV
on your own network traffic.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai