Scenario review
Identity compromise, MFA abuse, and BEC/session theft focus areas
Assessment workspace preview
Open the assessment workspace preview to see which use cases are covered, blocked, noisy, or missing proof, then follow the evidence path behind the highest-priority gaps.
Evidence Ledger
Priority
High
Priority
High
Identity risk
Telemetry gap
MFA logs
Validation blocked
Evidence
Replay notes
Reviewer linked
SOC route
Identity queue
Owner assigned
Monthly review
Readout
Executive artifact
Priority
High
Gap
MFA logs
Evidence
Replay notes
Review
SOC route
Assessment evidence for identity alert route, source blockers, reviewer notes, and executive readout.
| Evidence ID | Record | State | Source |
|---|---|---|---|
| VC-ID-014 | Identity compromise | Blocked | Identity logs |
| VC-VAL-021 | Replay notes | Ready | Rule review |
| VC-REL-008 | Route review | Human review | SOC queue |
| VC-MON-005 | Monthly review | Draft | Evidence board |
Telemetry gap: MFA audit fields missing; validation blocked.
Validation evidence: Replay notes and reviewer history attached.
SOC route: Identity queue and owner ready for review.
Identity compromise, MFA abuse, and BEC/session theft focus areas
Expected SOC route, noise notes, and false-positive pressure
Missing log sources and field gaps tied to detection risk
Validation records, owner trail, and reviewer notes
Human-approved change context and rollback notes
Monthly Detection Engineering Review priorities
Partner summary for portfolio revalidation
The guided preview starts with an identity-compromise evidence thread and ends with the assessment handoff your team would review.