Catch the chain

Five alerts become one incident before anyone is woken.

Detect, identity threat detection and response

Five alerts correlated on one person beside ten accounts correlated on one source address
01Where it goes wrong

A session hijack at 02:14. A login from 5,900km away at 02:28. A rule forwarding mail out of the building at 02:44. Three queues, and nobody joins them up.

For the SOC analyst working the queue.

02What the industry reports

What the industry reports

  • 22%of breaches begin with credential abuse, the single largest initial access vectorVerizon DBIR 2025
  • 88%of basic web application attacks involve stolen credentialsVerizon DBIR 2025
  • 54%of ransomware victims had credentials exposed in infostealer logs beforehandVerizon DBIR 2025
03What changes

What changes

Correlated on the identity and on the source

A queue grouped by user never finds the one address working through ten accounts. Both axes run, and what correlates with neither stays on its own.

The order is part of the signal

A session hijack, then travel that is not possible, then a forwarding rule. Sequence is what separates an incident from four coincidences.

The blast radius is already attached

Governance writes to the same graph. Triage opens with what that account reaches, instead of a lookup somebody has to run.

04What it covers

Everything this covers.

Connected sources and the four Microsoft 365 audit subscriptions, with events arriving live from Exchange
01Signal coverage
01

Signal coverage

  • Sign-in and audit events from the directory
  • Six Microsoft 365 workloads, where an inbox rule would otherwise be invisible
  • The connections screen names which subscriptions are live
Connected sources and the four Microsoft 365 audit subscriptions, with events arriving live from Exchange
02

Detection

  • Rules in a Sigma-compatible schema, mapped to MITRE ATT&CK
  • Impossible travel measured on real geography and speed
  • A subnet hop told apart from one across a continent
  • Password spray counted on failures across distinct accounts
  • Legacy authentication downgrade caught on its own
A detection rule in its Sigma-compatible form, with the technique it maps to and its known false positives
03

Correlation

  • Correlated on the identity and on the source address
  • Events held in the order they happened
  • Suppression rules mute the known-good and collapse duplicates
Five alerts on one account laid out on a time axis, each with its technique and the gap since the last one
04

Response

  • Every rule ships its own ordered response steps
  • Detection and governance read one graph
  • A review of that account's access, opened from the same conversation
The response steps the rule ships with the alert, in order, with the first already run by an analyst
05What does the work

The parts of the product this uses.

Threat detectionRules read like detections and map to the techniques they catch
Correlation and attack chainsRelated events arrive as one chain instead of separate tickets
InvestigationsThe timeline, the attack path and the evidence arrive assembled
Guided responseEvery rule ships the playbook for the thing it just caught
06On your own tenant

See it on your own tenant.

Book a demo

Connect your directory and see findings the same day.

The graph behind it