Risk reduction · Security detection

Detect early signs of compromise

Early attack activity often appears as a set of weak signals that do not individually cross an alert threshold.

The record

Telemetry these decisions draw on

  • Failed and successful logins
  • MFA events
  • Device changes
  • New API keys
  • Privilege escalation
  • Unusual data access
  • Command execution
  • Network connections
  • Cloud-resource creation

The questions

What an agent answers

  • Is this activity normal for the user or workload?
  • Which weak signals form a suspicious sequence?
  • Has an attacker established persistence?
  • What systems or data are now at risk?
  • What should be contained immediately?
Example agent output
"This is not normal travel activity. The account authenticated from a new device, bypassed the usual MFA flow, created an API key, and accessed customer data outside its historical pattern."

We use cookies to provide essential site functionality and, with your consent, to analyze site usage and enhance your experience. View our Privacy Policy