Forensics on the Edge: Reconstructing the Ivanti Exploit Chain
When your security perimeter becomes the initial access vector, traditional incident response playbooks fail.

The perimeter security appliance is the ultimate irony in modern network architecture. You purchase a proprietary black box, bolt it directly to the public internet, and trust it to gatekeep your most sensitive internal subnets. But beneath the polished web interface and corporate branding, that appliance is usually just a bespoke Linux distribution running web servers and interpreters that have not been updated in years.
The recent exploitation of Ivanti Connect Secure gateways by the threat actor UNC5221 laid this vulnerability bare. Attackers realized that if they could compromise the edge appliance, they bypassed the initial access lottery entirely. They owned the gateway, intercepted the credentials in plaintext, and operated from a device where security teams literally cannot deploy endpoint detection agents.
Reconstructing an attack on a closed system requires throwing out the host-centric playbook. We have to look at the artifacts left behind when attackers chain vulnerabilities, drop custom webshells, and subvert the appliance from the inside out.
The Perimeter as Patient Zero
Network appliances exist in a privileged, highly exposed state. They are designed to parse untrusted external traffic while simultaneously maintaining trusted connections to internal directories, authentication servers, and core infrastructure. This dual nature makes them high-value targets for initial access brokers and state-sponsored actors alike.
The Perfect Black Box
Defenders face a massive visibility gap at the edge. The operating systems on these devices are heavily locked down by the vendor, preventing administrators from installing standard telemetry tools. You cannot deploy EDR sensors or memory inspection tools on a closed-box VPN gateway. When a compromise occurs, you cannot simply query process execution history through your centralized console.
UNC5221 exploited this exact blind spot during their campaign. By operating entirely within the boundaries of the compromised appliance, the threat actor maintained persistent access for weeks. They understood that security operations centers implicitly trust traffic originating from the VPN gateway, creating a massive blind spot right where the network should be most heavily monitored.
Deconstructing the Exploit Chain
The Ivanti compromise relied on an elegant chaining of two distinct vulnerabilities to achieve unauthenticated remote code execution. The first link in the chain was CVE-2023-46805, an authentication bypass vulnerability within the web component of the gateway. The appliance failed to properly sanitize requested URIs, allowing attackers to use directory traversal sequences to access restricted API endpoints.
The vulnerability stems from an architectural mismatch between the frontend web server and the backend application logic. The frontend server fails to normalize the URI before passing it to the backend route handler. This allows the traversal sequence to slip past the initial perimeter checks.
GET /api/v1/totp/user-backup-code/../../system/maintenance/archiving/cloud-server-test-connection
By appending the traversal payload to a nominally unauthenticated endpoint, the attacker bypassed the authentication checks enforced by the web server. This granted access to internal API routes that were never meant to be exposed to the internet. But authentication bypass alone is rarely the end goal.
The second half of the equation was CVE-2024-21887, a command injection vulnerability located in the very endpoints exposed by the first exploit. The system failed to sanitize user-controlled input passed into internal administrative scripts. By embedding shell commands within the JSON payload sent to these restricted endpoints, the attacker achieved remote code execution with root privileges, effectively taking full control of the underlying operating system.
Living Off the Appliance
Achieving root execution is only the beginning of a persistent campaign. Rather than dropping compiled binaries that might trip external network signatures, attackers prefer to live off the appliance. In the Ivanti campaign, they wrote custom webshells directly into the existing Perl scripts that power the appliance web interface.
Trojanizing the Core
Incident responders identified several variations of these webshells, tracking them under names like GLASSTOKEN and GIFTEDVISITOR. The attackers modified legitimate files on the filesystem, such as the components used to handle SAML authentication. By injecting just a few lines of Perl, they turned core system files into backdoors that could evaluate arbitrary code passed in via specific HTTP headers or POST bodies.
A common technique involves modifying a core authentication handler script. The injected Perl code checks for the presence of a specific, obscure HTTP header in incoming requests. If this header is present, the script extracts its value, decodes it, and passes it to the evaluate function. This creates a stealthy, memory-resident execution environment. To an external vulnerability scanner, the web interface behaves normally. To the attacker holding the correct HTTP header, it is a fully functional root command prompt.
The operational danger of this approach lies in credential harvesting. Because the compromised scripts actively processed user logins, the attackers could silently dump plaintext passwords, session tokens, and multifactor authentication codes into hidden files. Even if a user successfully authenticated and connected to the VPN, their credentials were simultaneously intercepted and staged for exfiltration.
The Reality of Edge Gateway Telemetry
Conducting proper vpn appliance forensics requires accepting that the device itself is an unreliable narrator. If an attacker has root access, they can manipulate, delete, or selectively pause local logging mechanisms. You cannot trust the syslog daemon running on a machine controlled by the adversary.
When the appliance itself is compromised, its internal logs are the first casualty of the intrusion. Forensic reconstruction must pivot to external, immutable data sources.
Security teams must rely on network flow data, firewall logs, and upstream authentication logs. NetFlow and PCAP data are critical for identifying anomalous outbound connections originating from the appliance. Defenders should look for outbound connections originating from the appliance management IP addresses directed towards unknown external infrastructure.
Appliances generally only need to communicate with known update servers, NTP pools, and internal directory services. A sudden burst of HTTPS traffic to an unclassified domain is an immediate indicator of compromise. Internally, if the appliance suddenly initiates SMB connections over port 445 to internal file shares, or begins conducting port scans against internal subnets, the gateway has been weaponized.
Similarly, analyzing upstream authentication systems can reveal the scope of the credential harvesting phase. If your identity provider system log shows a sudden spike in successful logins from unusual geographic locations using VPN IP pools, it strongly suggests the session tokens generated by the appliance have been compromised and replayed.
Designing for Inevitable Compromise
The core lesson from these edge exploitation campaigns is that gateways will eventually fall. Network architecture must evolve from a perimeter-centric trust model to one of assumed breach. The VPN gateway can no longer be treated as a trusted internal asset simply because it facilitates employee access.
Enforcing East-West Segmentation
Network engineers must implement strict east-west segmentation. The gateway should exist in a heavily restricted network zone. Firewalls must explicitly drop all traffic from the VPN subnet to internal administrative interfaces, hypervisor management networks, and backup infrastructure.
If a user needs administrative access to an internal server, they should route through a dedicated privileged access workstation, not directly from the general VPN pool. Every internal application must enforce its own identity verification and continuous authorization.
Application-level controls compensate for network-level failures. Enforcing identity verification at the application layer ensures that even if the gateway is completely compromised and credentials are harvested, the internal blast radius remains contained by contextual access policies.
The takeaway
The exploitation of edge gateways is a masterclass in attacking the blind spots inherent to perimeter appliances. By chaining path traversal with command injection and embedding custom Perl webshells into core system files, threat actors turn the very devices meant to secure the network into untraceable staging grounds. Because the appliance is a black box, traditional endpoint forensics are useless.
Defenders must adapt by shifting their forensic focus to external network telemetry and architecting internal networks to withstand edge gateway failures. Tools like MailSleuth.AI can help analysts correlate these disparate log sources across identity providers, edge networks, and internal infrastructure, bringing much-needed visibility to the shadows of the perimeter. If you treat your edge appliance as an implicitly trusted bastion, you are one vulnerability away from a total network compromise.
We dissect phishing campaigns and email infrastructure so you don't have to.


