01 / THE PROBLEM
A valid account can make hostile activity look ordinary.
Identity compromise investigation connects authentication, MFA, entitlement, endpoint, cloud and application evidence around the same identity. The goal is to determine which sessions, credentials and resources are affected, then contain that path without disabling more of the business than necessary.
Attackers who gain a valid account can authenticate through expected services, use legitimate administration tools and inherit the user’s normal access. The evidence rarely arrives as one decisive alert. A risky login, password change, new MFA method, unusual token, endpoint process and cloud action may each appear in a different system.
The analyst must answer a connected question: is this still the real user, and if not, how far has the identity travelled?
02 / INCIDENT PATH
Five signals. One story.
Consider a workforce account with access to email, a managed laptop and a cloud administration portal. The first signal looks weak. The sequence changes its meaning.
- 08:42
New authentication context
A successful login appears from a location and device posture not seen for this identity. The login alone may be travel, a VPN or theft.
- 08:47
MFA method changes
A new authentication method is registered. The original user has not previously performed this change from the active session.
- 08:55
Privilege path opens
The account requests access to an administrative role and reads a set of secrets outside its normal work pattern.
- 09:03
Endpoint context diverges
The managed laptop remains active in its expected location while the new session continues elsewhere.
- 09:08
Data access expands
The new session reaches a cloud storage and collaboration scope that the identity has not accessed in the baseline period.
03 / VIRIAN INVESTIGATION
Follow the identity, not the queue.
Scope holds the current identity, device, entitlement and connection state. Hunt starts from the triggered signal, tests whether the activity matches a legitimate explanation and expands only where the evidence points.
Establish the identity state
Compare current credentials, MFA methods, active sessions, device bindings, groups, roles and recent administrative changes.
Separate the sessions
Correlate location, device, token, client, endpoint and timing to determine whether the activity can belong to one user.
Trace downstream access
Find resources, secrets, applications and cloud actions reached by the suspect credentials or tokens.
Test legitimate explanations
Check travel, support activity, approved privilege elevation, device replacement and known automation before reaching a hostile verdict.
04 / DECISION RECORD
The verdict carries its proof.
Virian does not treat enrichment as the outcome. The incident record connects each material claim to the source that supports it and preserves the reasoning, policy and action state.
Source events
Authentication, MFA, token, directory, endpoint, cloud and application records remain linked with time and provenance.
Affected path
The identity, suspect sessions, credentials, devices, roles and resources are recorded as a connected scope.
Competing explanations
Supported, rejected and unresolved hypotheses remain visible instead of being hidden by a confident summary.
Policy and approval
The record shows which actions were allowed, which required approval and who made the consequential decision.
05 / CONTROLLED RESPONSE
Contain the affected path.
Strike checks policy, routes approval where required and takes actions for the compromised path. The response can change with asset criticality, confidence, business impact and the reversibility of each action.
| Response | Purpose | Control consideration |
|---|---|---|
| Revoke suspect sessions | Stop active use of stolen tokens while preserving known-good access where possible | Scope revocation to the identified sessions or require wider revocation when session separation is uncertain |
| Reset credentials and MFA | Remove attacker-controlled authentication material | Verify the recovery channel and prevent the suspect session from registering replacement methods |
| Suspend privileged roles | Close the path to sensitive administration and data | Route approval for business-critical or emergency accounts |
| Isolate the affected endpoint | Contain a device involved in credential theft or session persistence | Confirm operational impact and use time-bound isolation where appropriate |
| Increase observation | Watch linked identities, resources and tokens for recurrence | Set a clear monitoring period, owner and closure condition |
06 / PROOF DESIGN
Measure the current investigation, then run in shadow.
A useful proof begins with one identity signal and the minimum sources needed to test it. Compare Virian with the existing process on live cases before granting response authority.
Investigation coverage
What proportion of triggered identity signals receives a complete cross-system investigation?
Time to evidence
How long until the operator receives a supported path rather than a list of enriched fields?
Decision agreement
Where do Virian and analysts agree, disagree or require more evidence?
Containment precision
Can response stop the suspect path without unnecessary account, device or business disruption?
07 / PRIMARY SOURCES
Identity and access foundations.
- 01MITRE ATT&CK T1078, Valid AccountsTHREAT KNOWLEDGE
- 02NIST SP 800-207, Zero Trust ArchitectureNIST
- 03NIST SP 800-61 Rev. 3, Incident Response RecommendationsNIST · 2025
