Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

Could a denial-of-service attack come from inside the organisation?

Yes. A compromised device, malicious user, faulty script, broadcast storm, runaway job or failed deployment can disrupt services from an internal network or trusted platform.

Trace the true originating process

Preserve source device and process, account, route, target, command or configuration, preceding changes and response. Internal translation, gateways and load balancing may make one address represent many devices.

A trusted management or monitoring platform may trigger cloud, identity or backup effects. Obtain the upstream job, operator, authentication and configuration rather than attributing activity to the service account seen by the target.

Separate location from intent

An internal source does not prove an insider acted deliberately. The host may be compromised, the account shared or remotely controlled, or the process malfunctioning.

Correlate endpoint, switch, firewall, identity and management records before deciding origin. Then assess malicious direction, automation and accidental configuration as separate explanations.

Key takeaway

Investigate internal disruption through the complete process and management route, without equating an internal address or account with deliberate insider action.

Reference: CIM-204Cyber Incidents & Offender Methods