Old Logs Revealed the Akira Intrusion

The gap was not missing telemetry. The intrusion could be rebuilt from ordinary SSLVPN syslog and Windows EVTX, which means the real failure was that the logs were not kept long enough or joined fast enough to show the warning signs in time. The report reconstructs a recent Akira intrusion using only firewall authentication logs and Windows event data from a mid-sized Active Directory environment. It shows the early trail in VPN login failures and later Windows activity, with no EDR, memory capture, or packet data needed to recover the sequence. For teams that split remote-access and Windows logs across different systems, the same ransomware lead-up can vanish before anyone correlates it.

Part of the PlainSec briefing for 2026-05-28

Sources