Authentication triage¶
Ask: Who authenticated, from where, to what, how, whether MFA was used or changed, whether the device/geography/IP was normal, whether the account was privileged, and what happened immediately afterward.
High-interest patterns¶
| Pattern | Pivot next |
|---|---|
| Impossible or unusual travel | Session overlap, VPN/proxy, device IDs, token use |
| New country, IP, ASN, or device | Historical baseline, reputation, sibling accounts |
| MFA fatigue or method change | Prompt sequence, registration actor, later success |
| Password reset or new credential | Initiator, channel, recovery details, follow-on login |
| New group membership/privilege | Actor, group sensitivity, subsequent admin action |
| Service account interactive login | Logon type, source host, owner, scheduled use |
| Dormant account suddenly active | Reactivation/change events, source, actions |
| Failures followed by success | Password spray/brute force pattern and source scope |
| Login followed by admin action | Session/token continuity and resource impact |
Pivot next: Windows 4624/4625/4648/4672/4768/4769/4776, IdP sign-ins, MFA/conditional access, endpoint process lineage, mailbox/cloud audit, and network telemetry.