news.mlab.sh
Back to the feed
threat-intel

Inside the Modern SOC: The Identity Front Door

High
Summary

A significant trend in cyberattacks is the increasing reliance on compromised identities rather than exploiting technical vulnerabilities. Nearly 90% of Unit 42 investigations involved identity weaknesses, with 65% of initial access activity stemming from techniques like phishing, social engineering, and MFA manipulation. Attackers use these compromised identities to establish persistence, escalate privileges, and expand their access across multiple environments, often mimicking legitimate administrative behavior, to achieve objectives like ransomware deployment or data theft. Unit 42 recommends prioritizing identity context and consolidating telemetry to proactively identify and respond to these attacks.

A growing number of cyberattacks are bypassing traditional security controls by exploiting compromised identities, rather than targeting vulnerabilities in software or systems. According to the 2026 Unit 42 Global Incident Response Report, identity weaknesses played a central role in nearly 90% of investigations handled by Unit 42, with 65% of initial access activity directly linked to identity-based techniques. These techniques include phishing campaigns, social engineering calls, MFA fatigue attacks, and the misuse of help desk processes.

Once inside a network, attackers leverage these compromised identities to establish persistence, escalate privileges, and expand their access across various environments. This often involves mimicking legitimate administrative behavior, making it difficult for security teams to detect malicious activity until it has already progressed significantly. The escalating access can quickly transform a single compromised identity into a multi-domain investigation requiring defenders to connect activity across the entire environment.

Threat groups, such as Muddled Libra (aka Scattered Spider), are demonstrating how attackers increasingly rely on social engineering and identity abuse as part of their toolkit. The objective behind these attacks can range from ransomware deployment and data theft to long-term persistence.

Unit 42 utilizes the Cortex SecOps platform to unify security telemetry, enabling analysts to quickly validate suspicious activity and understand the full scope of an attack. Their 24/7 Managed Detection and Response (MDR) team continuously investigates suspicious activity, while threat hunters proactively search for signs of identity compromise. AI-driven correlation, behavioral context, and Unit 42 threat intelligence help teams quickly validate high-confidence incidents and determine the full scope of attacker activity.

To combat these evolving threats, Unit 42 recommends focusing on operational challenges that often prevent teams from detecting identity-driven attacks early. Prioritizing identity context – correlating identity activity with endpoint, cloud, and SaaS telemetry – is crucial. Reducing manual investigation by consolidating telemetry and investigations into a unified view will significantly speed up response times. Continuously improving detection by regularly refining detections, correlation rules, and response playbooks is also essential to keep pace with emerging identity-based threats. Protecting time for threat hunting helps uncover credential abuse, privilege escalation, and hidden persistence before they escalate into larger incidents.

Read the full article at Palo Alto Unit 42