Could a denial-of-service attack come from inside the organisation?¶
Yes. A compromised device, malicious user, faulty script, broadcast storm, runaway job or failed deployment can disrupt services from an internal network or trusted platform.
Trace the true originating process¶
Preserve source device and process, account, route, target, command or configuration, preceding changes and response. Internal translation, gateways and load balancing may make one address represent many devices.
A trusted management or monitoring platform may trigger cloud, identity or backup effects. Obtain the upstream job, operator, authentication and configuration rather than attributing activity to the service account seen by the target.
Separate location from intent¶
An internal source does not prove an insider acted deliberately. The host may be compromised, the account shared or remotely controlled, or the process malfunctioning.
Correlate endpoint, switch, firewall, identity and management records before deciding origin. Then assess malicious direction, automation and accidental configuration as separate explanations.
Key takeaway
Investigate internal disruption through the complete process and management route, without equating an internal address or account with deliberate insider action.