SOC Analyst · Lesson 3 of 8
Comparing authentication signals
An unusual sign-in can reflect compromise, travel, a network change, or a false alarm. Combine signals before making a claim about the user.
Follow the session, then test explanations
Fictional activity for jlee.
- First18 failed sign-ins
A pattern worth examining.
- NextOne successful sign-in
The system accepted the sign-in.
- ThenReporting app access
Related session activity adds context.
Read the visualWhat would help distinguish expected work from misuse?
Trusted owner verification, device and authentication context, and related session events.
Compare the sequence
Look for failures, success, session creation, and subsequent activity. Preserve event identifiers.
Validate context
Check device and authentication details, then verify expected activity using a trusted contact method. A location estimate is imperfect.
Name uncertainty
State which explanations remain possible. A successful login proves credentials were accepted, not who controlled them.
Put it in context
Eighteen failures precede a success for jlee. The session then accesses a reporting app. You have a sequence worth investigating, but not proof of data theft.
Accepted credentials do not establish the person behind a session.
Read the sources
Make it stick.
Try one short question to check your understanding and save this lesson to your progress.