Skip to content
CIM-204 Cyber Incidents & Offender Methods

Could a denial-of-service attack come from inside the organisation?

The practical answer

Yes. Disruptive activity may originate from an internal device, account, application or network segment.

The key evidential caution

The dangerous assumption is that denial of service must come from the public internet.

Internal causes may include:

Key points

  • compromised devices
  • malicious insiders
  • misconfigured applications
  • faulty scripts
  • broadcast storms
  • runaway jobs
  • internal scanning
  • abuse of administrative access
  • failed deployment

What investigators should establish

Investigators should identify:

Key points

  • the source device and process
  • account context
  • target service
  • network path
  • commands or configuration
  • whether the activity was authorised
  • what changed before the disruption
  • what happened after containment

An internal source does not automatically mean an insider acted deliberately.

The device may have been compromised or the process may have malfunctioned.

Evidential limits

Likewise, an internal account may be shared, automated or remotely controlled.

Preserve endpoint, network, account and management-platform records before remediation.

Internal disruption may cross network boundaries through shared infrastructure or management systems. A compromised internal host may trigger cloud, identity or backup effects that appear external. Preserve the full route and avoid assuming that the first internal address seen was the original controller.

If internal activity originated from a management or monitoring platform, preserve the upstream job, operator, account and configuration. The target may record only a trusted internal service even where the triggering action came from a compromised external account.

Internal routing, address translation and load balancing can obscure the original host. Correlate endpoint, switch, firewall and identity records before attributing the source. A shared internal address may represent many devices or a gateway rather than one user.

Operational takeaway

Investigate internal and external sources equally, and distinguish malicious intent, compromised devices, automation and configuration failure.

Keep moving

Where this question leads

These links explain why the next page may matter, rather than presenting an undifferentiated list.