We Investigated Every Alert for 90 Days β€” These 4 Threats Kept Winning

Β·
Listen to this article~3 min

We opened every security alert for 90 days straight. Identity attacks won half the time β€” and the reason why will change how you think about detection.

### The Quarter That Changed How We Think About Alerts For three months, we did something most security teams never get around to: we opened every single alert. Not triaged β€” actually investigated. May through July 2026, across multiple customer environments, thousands of signals. What we found wasn't a horror story. It was a pattern. And once you see it, you can't unsee it. ### Threat #1: Identity Was the Bullseye Here's the stat that stopped us cold: identity was the target in roughly half of all confirmed malicious activity. Not malware. Not zero-days. Identity. Think about that for a second. Attackers weren't breaking down the door β€” they were walking through it with stolen keys. Credential stuffing, session hijacking, MFA fatigue attacks. The boring stuff that works. Why did some succeed? Because the alerts fired, but nobody connected the dots fast enough. A failed login here, a password reset there β€” individually, they look like noise. Together, they're a story. ### Threat #2: Living Off the Land Attackers are ditching custom tools. Instead, they're using what's already on your systems β€” PowerShell, WMI, scheduled tasks. Nothing to detect because nothing new gets installed. > "The most dangerous attacks don't look like attacks. They look like Tuesdays." This one's tricky because your EDR tool sees legitimate processes doing legitimate things. The only tell is context β€” who ran it, when, and from where. ### Threat #3: The Slow Burn Some intrusions took weeks to unfold. Small footholds, quiet lateral movement, patient privilege escalation. No alarms because no single action crossed a threshold. We saw attackers spend 14 days just watching. Learning. Then striking in under an hour. ### Threat #4: Cloud Credential Sprawl API keys in repos. Overpermissioned service accounts. Tokens that never expire. The cloud made everything faster β€” including the blast radius when someone gets in. ### Why Some Attacks Succeeded The uncomfortable truth? Detection wasn't the problem. Correlation was. - Alerts lived in silos across different tools - No single view of identity behavior over time - Response playbooks assumed obvious malware - Teams were drowning in volume, not starving for signal ### What Actually Worked When attacks got blocked, it was almost always because someone asked a simple question: "Does this make sense for this user, right now?" Context beats volume. Every time. ### The Takeaway You don't need more alerts. You need fewer, better-connected ones. Identity-first thinking isn't a buzzword β€” it's the difference between a blocked attack and a breach report. Start with the boring stuff. It's where the real fights happen.