Skip to content

Authentication triage

Ask: Who authenticated, from where, to what, how, whether MFA was used or changed, whether the device/geography/IP was normal, whether the account was privileged, and what happened immediately afterward.

High-interest patterns

Pattern Pivot next
Impossible or unusual travel Session overlap, VPN/proxy, device IDs, token use
New country, IP, ASN, or device Historical baseline, reputation, sibling accounts
MFA fatigue or method change Prompt sequence, registration actor, later success
Password reset or new credential Initiator, channel, recovery details, follow-on login
New group membership/privilege Actor, group sensitivity, subsequent admin action
Service account interactive login Logon type, source host, owner, scheduled use
Dormant account suddenly active Reactivation/change events, source, actions
Failures followed by success Password spray/brute force pattern and source scope
Login followed by admin action Session/token continuity and resource impact

Pivot next: Windows 4624/4625/4648/4672/4768/4769/4776, IdP sign-ins, MFA/conditional access, endpoint process lineage, mailbox/cloud audit, and network telemetry.