A true story, statistically speaking

At 03:14, someone became your finance director.

A stolen token. A machine you’ve never seen. Four hundred documents gone by sunrise - and not one alarm, because every event, taken alone, looked legitimate. This page replays the breach your tools would sleep through. Scroll.

  • 03:14 sign-in
  • 03:16 unknown device
  • 03:17 hosting-provider ASN
  • 03:20 baseline broken
  • 06:05 blast radius
  • 06:12 access severed

The replay

  1. 03:14

    A valid token signs in

    No password prompt, no MFA challenge, no alert. The credential is legitimate - that’s the whole trick. Your EDR has never met this machine, so it has nothing to say.

  1. 03:16

    The machine that shouldn’t exist

    Never enrolled, never authenticated - accessing data with no observed sign-in at all. 1Security classifies it as a shadow device: reconstructed from real activity, keyed by a stable fingerprint, invisible to Intune by definition.

  1. 03:17

    The origin that doesn’t fit

    A hosting-provider ASN in a country you don’t operate in. Locations resolve every action to country, city and network - with Microsoft’s own datacenter noise already labelled out, so this origin actually means something.

  1. 03:20

    Four times the usual appetite

    File activity spikes past this account’s own 30-day baseline. Anomalies opens an episode - per-user baselines, episodes not events, and an alert line you position yourself.

  1. 06:05

    The blast radius, exactly

    Which 340 files, which two accounts, which sessions, from where. Per-action attribution over a three-year memory - the investigation that used to take 12 hours of log stitching, done in 10 minutes.

  1. 06:12

    Severed, staged, documented

    Access revoked, links expired, every action recorded in a review ledger. Composite revocation understands the permission graph - direct grants, links, groups, sites - and asks before touching anything that would affect other people.

Epilogue

Your tools saw all of this. They just had no reason to care.

Every event in this story appeared in a log somewhere. The sign-in was valid, the device was silent, the origin was an IP address nobody resolved, and the download volume was just a number without a baseline. The breach wasn’t invisible - it was unassembled.

We’re not selling fear. We’re selling sight: the same events, assembled into one story, while it’s still 03:20 and not the morning after.

Replay this on your own tenant.

Connect read-only and see what the last 90 days actually looked like - shadow devices, strange origins, broken baselines and all.