惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

T
Threatpost
WordPress大学
WordPress大学
Martin Fowler
Martin Fowler
博客园 - 聂微东
L
LangChain Blog
D
Docker
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
D
DataBreaches.Net
aimingoo的专栏
aimingoo的专栏
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
腾讯CDC
C
Cisco Blogs
L
LINUX DO - 热门话题
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
Forbes - Security
Forbes - Security
C
Cybersecurity and Infrastructure Security Agency CISA
博客园 - 三生石上(FineUI控件)
S
Secure Thoughts
N
News and Events Feed by Topic
Latest news
Latest news
PCI Perspectives
PCI Perspectives
TaoSecurity Blog
TaoSecurity Blog
博客园 - 司徒正美
量子位
Stack Overflow Blog
Stack Overflow Blog
Know Your Adversary
Know Your Adversary
SecWiki News
SecWiki News
美团技术团队
C
CERT Recently Published Vulnerability Notes
Attack and Defense Labs
Attack and Defense Labs
AWS News Blog
AWS News Blog
C
Check Point Blog
S
Security Affairs
Vercel News
Vercel News
Google DeepMind News
Google DeepMind News
K
Kaspersky official blog
IT之家
IT之家
A
About on SuperTechFans
Help Net Security
Help Net Security
博客园 - 【当耐特】
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Recorded Future
Recorded Future
月光博客
月光博客
博客园_首页
小众软件
小众软件
H
Help Net Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
爱范儿
爱范儿

Vectra AI Blog

Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Why You Need an NDR to Protect Your Modern Network Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI named in Gartner hype cycle for security operations 2025 Vectra AI Vectra AI How Sanofi Detected and Stopped a Cyberattack How MITRE ATLAS Helps Detect LLM Attacks in Cloud AI Detecting Iranian APT identity attacks across hybrid environments Vectra AI Vectra AI Vectra AI Breaking down the axios supply chain incident Vectra AI Vectra AI Who’s Doing What on Your Network? FortiClient EMS Zero-Day: When the Control Plane Becomes Initial Access Detecting Compromise After the Axios Supply Chain Attack. Vectra AI Vectra AI Vectra AI AI Is Now the Attack Surface: Why Your Security Stack Must Adapt Fast Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How attackers use Brute Ratel (BRC4) Vectra AI Vectra AI Vectra AI The Cutting Edge: AI’s Inevitable Rise in Offensive Security Vectra AI Vectra AI Is AI the Right Tool to Defend Against Modern Cyberattacks? Vectra AI Vectra AI Vectra AI Turns Out Network Security Is Cool Again – and It’s Called NDR Vectra AI Vectra AI Vectra AI Choosing the Right NDR: Gartner’s 5 Questions Every Security Buyer Should Be Asking Vectra AI Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Identity Threat Detection and Response (ITDR) Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI You Have the Right Tools. So Why Are Attackers Still Getting In? Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Challenges in Microsoft Log Monitoring: Insights for Your SOC Vectra AI Platform Visualizes Multi-domain Modern Attacks with Attack Graphs Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI Gartner Security and Risk Conference – Chaos meets Opportunity Vectra AI Named a Leader and Outperformer in the 2025 GigaOm Radar Report for Network Detection and Response (NDR) Presenting the 2025 Vectra AI Scholars Simplify Threat Investigation and Hunting with Pre-built Queries in Vectra Investigate The 2025 Gartner® Magic Quadrant™ for Network Detection and Response (NDR) - Why Vectra AI Stands Tall Vectra AI Vectra AI Vectra AI Vectra AI Vectra AI How Black Basta Turned Public Data into a Breach Playbook Play’s New Tactics Bypass Traditional Defenses. Are You Ready? Charting a New Era of Network Security: Vectra AI at the Forefront Unlocking Operational Efficiency: How Vectra AI Drives 40% Gains in SOC Performance and 391% ROI Identity-Centric Attacks: The New Reality for UK Retail CISA Flags Fast Flux as a National Threat: Are You Covered? AI Agents: What Do They Mean in Cybersecurity?
Vectra AI
Zoey Chu · 2026-04-22 · via Vectra AI Blog

Most security teams assume they’ll know when an identity is compromised. We got the tools. An alert will fire. A control will fail. Something will clearly signal that an attacker has gained access. In fact, 80% of defenders believe their tools provide adequate protection across hybrid, multi-cloud environments.

In practice, it rarely works that way.

One customer recently found valid corporate credentials for sale on the dark web for $6. This was not a part of a targeted intrusion. It was just one entry in a long list of harvested accounts. With attackers now using AI agents to automate credential harvesting and validation, access is continuously generated, tested, and resold at scale.

Attackers understand this dynamic. And increasingly, they exploit it.

In most environments, an identity compromise doesn’t announce itself. The biggest challenge today isn’t stopping identity-based attacks but recognizing that they’ve already happened — and recognizing them may be harder than we think.  

  • Fact: All hybrid attacks eventually become identity attacks. Despite millions spent on security, 90% of organizations have experienced one.
  • Fact: 31% of users are service accounts with high access privileges and low visibility, and a single AD misconfiguration can introduce, on average, 109 shadow admins.
  • Fact: 90% of enterprises that experience identity attacks had MFA in place.

The challenge is only getting worse.

We’re no longer just defending human identities. Non-human identities (service accounts, APIs, workloads, and increasingly AI agents) are rapidly proliferating, often outnumbering humans. They operate continuously, authenticate programmatically, and interact across systems at machine speed. At the same time, attackers are using AI to scale their attacks and blend into normal identity behavior faster than ever.

The result: more identities, less visibility, and attacks that move faster than traditional detection.

Silence is the signal of identity compromise

Limited visibility into identity activity increases the chance of missing compromise.  

Modern enterprises span cloud, SaaS, network, and remote access. Identities move fluidly across all of them. Most security stacks don’t. Visibility remains fragmented, creating gaps where attackers operate undetected.  

When nothing looks wrong, it doesn’t mean we’re not secure. It can mean we just can’t see what’s happening. This gap widens in AI-driven environments. As AI agents and automation pipelines continuously access systems, identity activity increases exponentially, making it harder to distinguish normal from malicious behavior. At machine speed, blind spots scale.

Identity compromise shows up after login

Security has long focused on access like passwords, MFA, and authentication flows.  But attackers have adapted. Once inside, they behave like legitimate users.  

The real signal isn’t the login, but what happens next.  

In many incidents, the first visible signal isn’t authentication at all. It’s a user querying unfamiliar systems, accessing admin APIs, or requesting Kerberos tickets across multiple hosts. Each action is valid on its own. Together, they reveal lateral movement.

Unusual access patterns, unexpected system interactions, and sudden data access. These are indicators that matter but often fall outside traditional controls.  

Malicious activity looks legitimate

Attackers don’t hack in. They log in.  

In recent SaaS breaches, attackers didn’t steal passwords. They stole authentication tokens from a third-party integration and replayed them. No login prompt. No MFA. Just valid sessions.. From the system’s perspective, everything looked legitimate.

By using valid credentials, attackers blend into normal operations, leveraging existing permissions, moving through trusted pathways, and avoiding alert triggers. This is especially true for non-human identities, which often have high privileges but little behavioral monitoring. They don’t use MFA, operate continuously, and are harder to validate, which makes them easier to abuse. As AI adoption grows, so does this attack surface.

In one common pattern, attackers obtain a long-lived API key or service account tied to a data pipeline. The identity behaves as expected by pulling data, accessing storage, and calling APIs, but with subtle differences like slightly different datasets, timing, or destinations. There is no login anomaly, only behavioral changes.

“Normal” becomes the perfect disguise.

Prevention doesn’t equal detection

We rely heavily on controls like MFA and EDR. While essential, they weren’t designed to detect identity compromise, especially in AI-driven attacks.

Attackers can bypass MFA through phishing, social engineering, or compromised devices, then operate outside endpoint visibility using legitimate access.

Adversary-in-the-middle phishing kits now proxy authentication in real time. The user completes MFA, the attacker captures the session token, and immediately reuses it. From that point forward, the attacker operates as a fully authenticated user. No failed logins. No brute force. Just a valid session

The assumption that controls will make compromise obvious is flawed. In reality, they fail quietly. As attackers leverage AI to automate identity abuse, the gap between prevention and detection continues to grow.  

The signals are there...but disconnected

The clues of identity compromise do exist. But they are scattered.  

An authentication anomaly in one tool. Suspicious network activity in another. Cloud access patterns in a third. Without correlation, these signals remain isolated and inconclusive, creating noise instead of clarity.

This fragmentation worsens in AI-driven environments where identity spans more systems, moves faster, and generates more data than analysts can realistically correlate.

For example, a user logs in from a new location. Minutes later, that identity initiates unusual SMB traffic. Shortly after, it accesses unfamiliar cloud storage. Each event appears low-risk on its own and in separate tools. Only when connected across identity, network, and cloud does the attack become clear.

Rethinking how we detect identity compromise

The question isn’t whether identity compromise is happening. It’s whether we can see it.  

In the AI enterprise, identity compromise is more common, harder to detect, and faster to execute. More identities. More automation. More speed. More opportunity for attackers to hide in plain sight.

To close this gap, we need to evolve how we approach identity detection:

  • Assume compromise is inevitable and focus on finding attackers already inside
  • Treat identities as behavioral entities, not just credentials
  • Look for abnormal patterns and movement, not just authentication anomalies
  • Connect activity across identity, network, and cloud activity into a unified view
  • Prioritize high-confidence signals of attacker intent

Because the most dangerous attacker isn’t the one trying to get in. It’s the one who already has, and looks like they belong.

Learn more about Vectra AI’s approach to identity-based attacks: https://youtu.be/ytWOynLTAco