Identity is the new private network
Attackers don’t break in anymore. They log in.
600 million identity attacks a day, and the winning move is always the same: a valid login, doing things it shouldn’t. Your firewall, your EDR and your SIEM all watch it happen - and file it under normal. 1Security is built for the attack that looks like an employee.
- 600M/dayidentity attacks (Microsoft, 2024)
- 70%of breaches exploit excessive permissions
- 98%of granted permissions are never needed
The shift
The attack stopped being a break-in.
For twenty years a breach had a shape: an exploit, a payload, a malicious process. The industry built magnificent machinery to catch exactly that - and the machinery works. Which is precisely why attackers stopped doing it.
Today the winning move is a credential. A phished password, a stolen session token, an OAuth consent granted on a Tuesday and forgotten by Friday. There is no exploit to patch, no signature to match, no process to kill - just a valid login, exercising permissions it was legitimately given, at a scale nobody is watching.
The battlefield moved to the other side of the login screen. The tooling never followed.
The blind spot
Why your stack can’t see it.
Three tool categories, three excellent answers to the previous era’s questions.
Your SIEM stores the evidence
Every event of an identity breach lands in a log. But a SIEM stores records without understanding permissions - it can tell you what happened once you already know what to ask. It’s an archive, not a witness.
Your IAM provisions, then looks away
Identity platforms are superb at granting access and terrible at watching it. Once the permission exists, nobody tracks whether it’s ever used, by whom, or from where - and 98% of it is never needed at all.
Your EDR clears the machine
Endpoint tools inspect processes, and every process in an identity attack is clean. Outlook is Outlook, the browser is a browser. The credential is the malware - and no endpoint agent scans for that.
The answer
What it takes to catch a login.
A login-shaped attack has no signature - but it has tells. Catching it means correlating four things your tools keep in four different places, on one timeline: actor, device, location and behavior.
- 01
A device that shouldn’t exist
The token arrives from a machine that was never enrolled and never authenticated. 1Security reconstructs these shadow devices from real activity, keyed by a stable fingerprint - visible even when Intune has never heard of them.
- 02
An origin that doesn’t fit
A hosting-provider ASN in a country you don’t operate in. Every action resolves to country, city and network - with Microsoft’s own datacenter noise already labelled out, so an unfamiliar origin actually means something.
- 03
A baseline that breaks
The account suddenly reads four times its usual volume. Per-identity baselines turn “a number” into “an anomaly” - episodes, not events, with an alert line you position yourself.
The context
The map behind the timeline.
Detection tells you something is wrong. The permission graph tells you how bad: every file, site and mailbox the compromised account could reach - direct grants, sharing links, groups, inheritance - resolved in minutes. Blast radius used to be a week of log stitching. Now it’s a question with an answer.
The repair
From found to fixed.
Seeing the breach is half the job. 1Security carries every finding to its fix: revoke the access, expire the links, sever the sessions - through automations with grace periods and review queues, so nothing irreversible happens without a human deciding it should.
And until you deliberately consent to write access, everything runs read-only. You choose the day the map is allowed to act.
Proof and deployment
Counted, not promised.
No agents to deploy, no E5 upsell, no services engagement. Connect read-only in the morning and read your first findings the same day.
- 12h → 10 mina blast-radius investigation, before and after
- Same dayfrom read-only consent to first findings
- 3 yearsof activity memory - without a SIEM contract
- StandardMicrosoft licenses - no E5 prerequisite
Attackers don’t break in anymore. They log in.
See your tenant the way an attacker does - every identity, every permission, every login that doesn’t fit.
Or keep assuming every login is legitimate.