A little learning. A little more confidence.Your next step starts here

SOC Analyst · Lesson 3 of 8

Comparing authentication signals

An unusual sign-in can reflect compromise, travel, a network change, or a false alarm. Combine signals before making a claim about the user.

SEE THE IDEA

Follow the session, then test explanations

Fictional activity for jlee.

  1. First
    18 failed sign-ins

    A pattern worth examining.

  2. Next
    One successful sign-in

    The system accepted the sign-in.

  3. Then
    Reporting app access

    Related session activity adds context.

This sequence does not identify the person controlling the session or prove theft.
Read the visualWhat would help distinguish expected work from misuse?

Trusted owner verification, device and authentication context, and related session events.

Compare the sequence

Look for failures, success, session creation, and subsequent activity. Preserve event identifiers.

Validate context

Check device and authentication details, then verify expected activity using a trusted contact method. A location estimate is imperfect.

Name uncertainty

State which explanations remain possible. A successful login proves credentials were accepted, not who controlled them.

Put it in context

Eighteen failures precede a success for jlee. The session then accesses a reporting app. You have a sequence worth investigating, but not proof of data theft.

Accepted credentials do not establish the person behind a session.

Read the sources

Make it stick.

Try one short question to check your understanding and save this lesson to your progress.

YOUR LEARNING SPACE