Identity Threat Investigation

Investigate a suspected account or identity compromise in Entra ID (Azure AD), Okta, Google Workspace, or on-prem Active Directory: analyze sign-in logs for impossible travel, new country or ASN, MFA fatigue, legacy auth, token replay and AiTM session hijack; check risky OAuth consent grants, MFA method changes, mailbox rules, and privilege changes; spot AD attack indicators (Kerberoasting, AS-REP roasting, DCSync, golden and silver tickets, NTDS theft); and contain in the right order (reset, revoke sessions, disable, remove consent, krbtgt double reset) without breaking the business. Use it whenever someone says a user "got phished", "clicked the link", "approved an MFA prompt they didn't request", reports a risky sign-in or Identity Protection / Okta ThreatInsight alert, asks "is this account compromised", pastes sign-in or Security event log exports, or mentions a suspicious inbox rule, unknown app consent, or new Global Admin, even if the word "identity" never appears.

ftrout Updated

File contents

ftrout/secops-claude-skills/tree/main/skills/identity-threat-investigation commit 866536c669

Frequently asked questions

npx skillmds@latest add ftrout/identity-threat-investigation