Case study banner: Malaysian Manufacturer Loses Four Months of Intrusion Evidence to Memory-Only Firewall Logging. Type: On-Demand Incident Response.

Memory-Only Firewall Logging Erases Four Months of Intrusion Evidence at a Malaysian Manufacturer

Published on
2 October 2026
Last updated on

The firewall kept its logs in memory alone, where they expired on a rolling basis, so the intrusion's first four months left no trace. What survived showed over 20 administrator accounts.

Key facts

Organisation
Malaysian manufacturer, small regional office
Threat
Perimeter firewall compromise, administrative persistence and credential theft
Initial access
Undetermined. No log data survives from the period in which the foothold was established
Impact
Full firewall configuration stolen twice, every stored credential compromised, packet captures exfiltrated, a remote-access tunnel opened into internal file storage
Core issue
Memory-only logging with every off-device destination disabled, and no configuration revision history

What this case shows

  • An appliance that logs only to memory cannot support an investigation; the evidence expires on a rolling basis whether or not anyone is attacking.
  • Deleting unauthorised administrator accounts does not complete remediation where application programming interface keys and a stolen configuration file remain in the adversary's hands.
  • When a storage system lacks access logging, declaring "no evidence of access" is distinct from asserting "no access occurred" — only the former finding is valid.

Blackpanda's responders reconstruct intrusions from whatever evidence survives: see IR-1 assurance subscriptions and incident response.

What this would have cost with Blackpanda IR-1 in place

ODIRIR-1
Type of engagementOn-demand incident responseYearly subscription
Hours covered75 hoursUnlimited*
Pricing1USD $37,500USD $3,750

* Unlimited for one incident per year

1 Ad-hoc incident response pricing based on average market rates, from USD 500 per hour. Blackpanda IR-1 subscription pricing based on no. of endpoints, costing approx. 10x less than ad-hoc and retainer-based incident response. All figures are illustrative only, for guidance and marketing purposes and not to be relied upon by the reader. Actual incident response costs vary by scope, complexity, and provider.

‍

CHALLENGE

A Malaysian manufacturer operated its regional office on a deliberately small footprint: no directory domain, no endpoint detection and response platform, and no centralised logging. A single perimeter appliance delivered firewalling, wireless access and remote access, while two network-attached storage devices held the company's business records together with passport copies and bank statements. Operating without incident for several years, the setup triggered no security alerts.

In June 2026, the company's network integrator, carrying out unrelated work, found unauthorised administrator accounts and an active remote-access configuration on the firewall. It deleted the accounts, disabled the remote-access service and escalated. Blackpanda was engaged shortly afterwards to establish how the compromise had occurred, what the threat actor had done, whether personal data had been accessed or removed, and whether any foothold remained.

The investigation established that a threat actor had held administrative control of the appliance for at least four months, from February 2026 until containment. However, the initial access vector could not be determined, and the reason was architectural rather than evidential: the model has no log disk, every remote logging destination was switched off, and records therefore sat in a fixed-size memory buffer that overwrote its oldest entries continuously. Only the final weeks of the intrusion survived in any log. Every unauthorised administrator account predated the oldest surviving entry, so no creation event, timestamp or source address existed for any of them. This is a recurring pattern in perimeter firewall compromise cases, where the device that holds the organisation's trust boundary is also the device least equipped to explain its own history.

What the surviving window did show was the scale of the position the threat actor had built. The configuration recovered moments before remediation held more than 20 administrator accounts, all carrying super-administrator privilege, only one restricted to a trusted source address and none protected by multi-factor authentication. Furthermore, the complete configuration file had been downloaded twice in June 2026, which exposed every administrator password hash, both application programming interface keys, the remote-access credential, the wireless pre-shared key and the full network topology.

→ PROTECT MY ORGANISATION TODAY

‍

SOLUTION

1. Reconstructed the intrusion from the surviving memory-resident log window

Blackpanda exported the appliance's memory-resident event logs before any further restart could clear them, then captured its running configuration and command-line state directly from the live device. Because the buffer had already rolled, the team treated the surviving window as a sample rather than a record, and stated explicitly which questions it could and could not answer.

2. Established the extent of administrative persistence from two configuration exports

Comparing the pre-remediation and post-remediation configurations identified every unauthorised account, the two application programming interface accounts, a disabled-but-intact local account, a dedicated remote-access portal, and a firewall rule permitting traffic from the virtual private network to any internal destination with traffic logging suppressed. Crucially, the analysis distinguished between persistence mechanisms that a password reset would close and those it would not; application programming interface keys fall into the second category, as do accounts reachable from any address on the internet in the absence of multi-factor authentication.

3. Defined the scope of the data inquiry strictly by the extent of the available evidence

Blackpanda collected the connection and transfer databases from the first storage device, a full filesystem timeline from the second, and triage collections from all three workstations. The first device had refused every connection attempt across its full retained history, which established that no authenticated session was ever obtained on it. The second device, however, writes no access log at all, so the absence of records there was reported as a property of its configuration rather than as evidence that nothing was read.

4. Confirmed containment and tested the conclusion against a further month of logs

Having established that no threat-actor authentication had succeeded after the integrator's intervention, Blackpanda tested that position against firewall logs running a further month beyond containment, and against execution artefacts on the workstations covering the whole intrusion period. No additional unauthorised access was found, and no evidence of ransomware, data destruction or service disruption was identified.

→ PROTECT MY ORGANISATION TODAY

‍

RESULTS

1. Administrative persistence enumerated and closed

All but one of the unauthorised administrator accounts had been deleted during containment, and Blackpanda identified the residual objects the integrator had disabled rather than removed, each of which retained an intact password hash.

2. Credential exposure defined rather than estimated

Because the configuration file had been downloaded in full, every credential stored on the appliance was assessed as compromised, which converted an open question into a finite reset list covering administrator passwords, both application programming interface keys and the wireless pre-shared key.

3. Data exposure scoped, with two uncertainties stated in both directions

No evidence was found that any file was read from the first storage device, while access to the second could be neither confirmed nor excluded; separately, the contents of the exfiltrated packet captures remain unknown and unrecoverable, so the possibility that they carried personal data in transit stands.

4. Remediation sequenced by what the evidence could support

Blackpanda recommended replacing the appliance rather than resetting it, on the basis that no record of its pre-intrusion state survives and a rebuilt unit could only be assumed clean; and recommended retiring or rebuilding the second storage device, which permits anonymous access to folders holding identity documents.

Upstream of this incident sit three conditions that cost nothing to correct and that would each have changed the outcome: logging forwarded off the device so that evidence outlives the buffer; multi-factor authentication on every administrative and remote-access path; and a periodic review of privileged accounts on perimeter equipment. The same pattern appears wherever network-attached storage sits on the same flat network as remote-access clients, because a single permissive rule then reaches the organisation's most sensitive records in one hop.

→ PROTECT MY ORGANISATION TODAY

‍

FREQUENTLY ASKED QUESTIONS

1. How can an intrusion last four months without anyone noticing?

Nothing in this environment was watching. There was no endpoint detection platform, no centralised logging and no alerting on the perimeter device, and the threat actor made no change that interrupted a business process. Detection came only when a third party happened to inspect the firewall's configuration for unrelated reasons.

2. Why could Blackpanda not determine how the attacker first got in?

The appliance retained no logs on permanent storage, and every option to forward events to an external system had been left switched off. Records sat in a fixed-size memory buffer that discarded its oldest entries as it filled, so the earliest surviving entry postdated the creation of every unauthorised account. Collecting the evidence again would not recover it, because the data no longer exists anywhere.

3. Does "no evidence of data theft" mean no data was taken?

No, and the distinction matters commercially as well as legally. On the first storage device there is positive evidence of refusal: no authentication from the relevant source ever succeeded across its full retained history. On the second there is no access log at all, so nothing can be concluded in either direction, and the exfiltrated packet captures are unrecoverable, which leaves a genuine residual possibility rather than a resolved one.

4. If the accounts were deleted, was the problem solved?

Deleting accounts addresses one persistence mechanism out of several. Application programming interface keys continue to function after a password-only reset, and a stolen configuration file hands over every stored credential plus the network topology, so remediation here required a full credential reset and, on Blackpanda's recommendation, replacement of the hardware itself. A comparable pattern appears in a remote-access appliance intrusion at a regional industrial manufacturer, where the entry path survived the first round of clean-up.

5. Is a firewall really a likely point of entry?

Increasingly so. Verizon's 2026 Data Breach Investigations Report found that exploitation of vulnerabilities has become the most common initial access vector for breaches, reaching 31% of its dataset; while credential abuse, the previous leader, fell to 13%. Edge and remote-access infrastructure sits squarely in that category, and it is frequently the one asset class an organisation has no second control over.

6. What should a small office with no security team do first?

Three measures carry disproportionate weight:

  • Forward logs off the device. Send firewall and remote-access events to an external destination so evidence survives a reboot or a full buffer.
  • Enforce multi-factor authentication on every administrative and remote-access login, without exception for service or maintenance accounts.
  • Review privileged accounts quarterly on internet-facing equipment, and retire protocols and devices that cannot log access at all.

WHAT THIS MEANS FOR YOUR ORGANISATION

The organisations most exposed to this pattern are not the ones with the largest attack surface; they are the ones whose perimeter device is simultaneously their firewall, their wireless controller, their remote-access gateway and their only witness. When that single appliance logs to memory alone and keeps no configuration history, an adversary who reaches administrative privilege inherits both the access and the record of it. Consequently, the investigative question shifts from what happened to what can still be proven, and the answer narrows every week the intrusion continues.

Two changes break the pattern, and neither requires a security team: evidence that leaves the device as it is generated, and a second factor on every administrative path. Beyond that, the decisive variable is how quickly a qualified responder can be in the environment once something is found, because the evidence that answers the hardest questions is the evidence that expires first. Blackpanda's IR-1 assurance subscriptions exist for that reason: the retainer, the scoping and the response hours are arranged in advance, so the response begins on the day of discovery — rather than after a procurement cycle.

→ PROTECT MY ORGANISATION TODAY

‍

ABOUT BLACKPANDA

Blackpanda is Asia's leading cyber incident response company, delivering digital emergency response across three integrated channels: IR consulting, IR-1 assurance subscriptions, and Lloyd's of London-underwritten cyber insurance. Each is purpose-built for a different buyer, whether enterprise, mass market, or sophisticated risk-transfer clients, and each stands alone as full incident response. Together, these channels reach the entire commercial market, because our mission is to provide digital emergency response for everyone. Buy all three and they combine into the complete post-attack recovery solution: preparation in advance, response the moment you're hit, and financial recovery paid for by insurance. One local team to help you get ready, respond, and recover.