A true story, statistically speaking
At 03:14, someone became your finance director.
A stolen token. A machine you've never seen. Four hundred documents gone by sunrise - and not one alarm, because every event, taken alone, looked legitimate. This page replays that night, assembled into one story. Scroll.
- 03:14 sign-in
- 03:16 unknown device
- 03:17 hosting-provider ASN
- 03:20 baseline broken
- 06:05 blast radius
- 06:12 access severed
The replay
- 03:14
A valid token signs in
No password prompt, no MFA challenge, no alert. The credential is legitimate - that's the whole trick. No endpoint agent has ever run on this machine, so the first trace of it is the data it touches.
- 03:16
The machine that shouldn't exist
Never enrolled, never authenticated - accessing data with no observed sign-in at all. 1Security classifies it as a shadow device: reconstructed from real activity, keyed by a stable fingerprint, listed alongside the devices you enrolled.
- 03:17
The origin that doesn't fit
A hosting-provider ASN in a country you don't operate in. Locations resolve every action to country, city and network - with cloud datacenter traffic already labelled as such, so this origin actually means something.
- 03:20
Four times the usual appetite
File activity spikes past this account's own 30-day baseline. Anomalies opens an episode - per-user baselines, episodes not events, and an alert line you position yourself.
- 06:05
The blast radius, exactly
Which 340 files, which two accounts, which sessions, from where. Per-action attribution over a three-year memory - the investigation that used to take 12 hours of log stitching, done in 10 minutes.
- 06:12
Severed, staged, documented
Access revoked, links expired, every action recorded in a review ledger. Composite revocation understands the permission graph - direct grants, links, groups, sites - and asks before touching anything that would affect other people.
Epilogue
Every event was logged. Nobody had put them together.
Every event in this story appeared in a log somewhere. The sign-in was valid, the device was silent, the origin was an IP address nobody resolved, and the download volume was just a number without a baseline. The breach wasn't invisible - it was unassembled.
We're not selling fear. We're selling sight: the same events, assembled into one story, while it's still 03:20 and not the morning after.
Replay this on your own tenant.
Connect read-only and see what the last 90 days actually looked like - shadow devices, strange origins, broken baselines and all.