VIRIAN
MENU
HomeOperating modelAgentic SOCCloud use caseDesign a proof

TRACE THE IDENTITY

Identity compromise.

One account can move across email, endpoints, cloud services and business systems. Virian connects the triggered signals into one intrusion path and carries the evidence with it.

9 minute readUpdated 15 July 2026Virian use case 01

01 / THE PROBLEM

A valid account can make hostile activity look ordinary.

Identity compromise investigation connects authentication, MFA, entitlement, endpoint, cloud and application evidence around the same identity. The goal is to determine which sessions, credentials and resources are affected, then contain that path without disabling more of the business than necessary.

Attackers who gain a valid account can authenticate through expected services, use legitimate administration tools and inherit the user’s normal access. The evidence rarely arrives as one decisive alert. A risky login, password change, new MFA method, unusual token, endpoint process and cloud action may each appear in a different system.

The analyst must answer a connected question: is this still the real user, and if not, how far has the identity travelled?

02 / INCIDENT PATH

Five signals. One story.

Consider a workforce account with access to email, a managed laptop and a cloud administration portal. The first signal looks weak. The sequence changes its meaning.

  1. 08:42

    New authentication context

    A successful login appears from a location and device posture not seen for this identity. The login alone may be travel, a VPN or theft.

  2. 08:47

    MFA method changes

    A new authentication method is registered. The original user has not previously performed this change from the active session.

  3. 08:55

    Privilege path opens

    The account requests access to an administrative role and reads a set of secrets outside its normal work pattern.

  4. 09:03

    Endpoint context diverges

    The managed laptop remains active in its expected location while the new session continues elsewhere.

  5. 09:08

    Data access expands

    The new session reaches a cloud storage and collaboration scope that the identity has not accessed in the baseline period.

03 / VIRIAN INVESTIGATION

Follow the identity, not the queue.

Scope holds the current identity, device, entitlement and connection state. Hunt starts from the triggered signal, tests whether the activity matches a legitimate explanation and expands only where the evidence points.

QUERY 01

Establish the identity state

Compare current credentials, MFA methods, active sessions, device bindings, groups, roles and recent administrative changes.

QUERY 02

Separate the sessions

Correlate location, device, token, client, endpoint and timing to determine whether the activity can belong to one user.

QUERY 03

Trace downstream access

Find resources, secrets, applications and cloud actions reached by the suspect credentials or tokens.

QUERY 04

Test legitimate explanations

Check travel, support activity, approved privilege elevation, device replacement and known automation before reaching a hostile verdict.

04 / DECISION RECORD

The verdict carries its proof.

Virian does not treat enrichment as the outcome. The incident record connects each material claim to the source that supports it and preserves the reasoning, policy and action state.

EVIDENCE

Source events

Authentication, MFA, token, directory, endpoint, cloud and application records remain linked with time and provenance.

STATE

Affected path

The identity, suspect sessions, credentials, devices, roles and resources are recorded as a connected scope.

UNCERTAINTY

Competing explanations

Supported, rejected and unresolved hypotheses remain visible instead of being hidden by a confident summary.

CONTROL

Policy and approval

The record shows which actions were allowed, which required approval and who made the consequential decision.

05 / CONTROLLED RESPONSE

Contain the affected path.

Strike checks policy, routes approval where required and takes actions for the compromised path. The response can change with asset criticality, confidence, business impact and the reversibility of each action.

ResponsePurposeControl consideration
Revoke suspect sessionsStop active use of stolen tokens while preserving known-good access where possibleScope revocation to the identified sessions or require wider revocation when session separation is uncertain
Reset credentials and MFARemove attacker-controlled authentication materialVerify the recovery channel and prevent the suspect session from registering replacement methods
Suspend privileged rolesClose the path to sensitive administration and dataRoute approval for business-critical or emergency accounts
Isolate the affected endpointContain a device involved in credential theft or session persistenceConfirm operational impact and use time-bound isolation where appropriate
Increase observationWatch linked identities, resources and tokens for recurrenceSet a clear monitoring period, owner and closure condition

06 / PROOF DESIGN

Measure the current investigation, then run in shadow.

A useful proof begins with one identity signal and the minimum sources needed to test it. Compare Virian with the existing process on live cases before granting response authority.

MEASURE 01

Investigation coverage

What proportion of triggered identity signals receives a complete cross-system investigation?

MEASURE 02

Time to evidence

How long until the operator receives a supported path rather than a list of enriched fields?

MEASURE 03

Decision agreement

Where do Virian and analysts agree, disagree or require more evidence?

MEASURE 04

Containment precision

Can response stop the suspect path without unnecessary account, device or business disruption?

07 / PRIMARY SOURCES

Identity and access foundations.

START WITH ONE IDENTITY SIGNAL

Prove the path before the action.

Connect the minimum identity, endpoint and cloud sources, run the investigation in shadow and measure the quality of the complete record.

Design the use case