A true story, statistically speaking

At 03:14, someone became your finance director.

A stolen token. A machine you've never seen. Four hundred documents gone by sunrise - and not one alarm, because every event, taken alone, looked legitimate. This page replays that night, assembled into one story. Scroll.

  • 03:14 sign-in
  • 03:16 unknown device
  • 03:17 hosting-provider ASN
  • 03:20 baseline broken
  • 06:05 blast radius
  • 06:12 access severed

The replay

  1. 03:14

    A valid token signs in

    No password prompt, no MFA challenge, no alert. The credential is legitimate - that's the whole trick. No endpoint agent has ever run on this machine, so the first trace of it is the data it touches.

  1. 03:16

    The machine that shouldn't exist

    Never enrolled, never authenticated - accessing data with no observed sign-in at all. 1Security classifies it as a shadow device: reconstructed from real activity, keyed by a stable fingerprint, listed alongside the devices you enrolled.

  1. 03:17

    The origin that doesn't fit

    A hosting-provider ASN in a country you don't operate in. Locations resolve every action to country, city and network - with cloud datacenter traffic already labelled as such, so this origin actually means something.

  1. 03:20

    Four times the usual appetite

    File activity spikes past this account's own 30-day baseline. Anomalies opens an episode - per-user baselines, episodes not events, and an alert line you position yourself.

  1. 06:05

    The blast radius, exactly

    Which 340 files, which two accounts, which sessions, from where. Per-action attribution over a three-year memory - the investigation that used to take 12 hours of log stitching, done in 10 minutes.

  1. 06:12

    Severed, staged, documented

    Access revoked, links expired, every action recorded in a review ledger. Composite revocation understands the permission graph - direct grants, links, groups, sites - and asks before touching anything that would affect other people.

Epilogue

Every event was logged. Nobody had put them together.

Every event in this story appeared in a log somewhere. The sign-in was valid, the device was silent, the origin was an IP address nobody resolved, and the download volume was just a number without a baseline. The breach wasn't invisible - it was unassembled.

We're not selling fear. We're selling sight: the same events, assembled into one story, while it's still 03:20 and not the morning after.

Replay this on your own tenant.

Connect read-only and see what the last 90 days actually looked like - shadow devices, strange origins, broken baselines and all.