Skip to main content
Category: Security · View source ↗
Connectors: none — works with Thread out of the box Role: Security & Compliance Owner, Technician Outcome: Faster Resolution & Response, Risk & Compliance When to use: Malicious or anomalous activity on an account where sign-in logs show MFA succeeded and no password change explains it; a user’s session appears active from an unfamiliar IP/device while the user is elsewhere; or post-phishing where the lure harvested a session (adversary-in-the-middle / token-replay), not just credentials. Run it: on one ticket (a suspected stolen-session case).

Prompt