Objective 1.2 · Lesson 2 of 2

Connect identities, applications, and email

Compromise can appear as normal application functionality used by the wrong person. Identity and business context are therefore as important as endpoint detections.

Investigate access that looks geographically impossible

Impossible-travel detections compare locations and times in authentication records. Treat the result as a lead: VPN exits, corporate proxies, mobile networks, and inaccurate IP geolocation can make a legitimate session appear to move unexpectedly. Examine session identifiers, authentication methods, device records, token use, and the person’s expected activity rather than demanding a physical travel explanation first.

A successful authentication does not resolve the case. Look for unfamiliar role assignments, changed authentication factors, newly created credentials, access to unusual resources, and actions outside the account’s normal responsibilities. Distinguish the human account from applications using its delegated access. A revoked password may not address every active session or separately issued credential.

Correlate application and cloud consequences

Service disruption may result from attack, overload, deployment errors, or a failing dependency. Join application error rates with access logs, change records, process events, and resource metrics. If a new configuration permits access that policy prohibits, investigate both the change and the subsequent use. An unauthorised setting matters even before you can demonstrate exploitation.

Cloud compromise may show up as an unexpected compute deployment, storage export, firewall change, or privilege grant. Attribute these control-plane actions to identities and assess whether their pattern matches an approved workflow. Missing endpoint alerts are weak reassurance when the affected service has no endpoint agent. Include provider audit coverage and account-level changes in your hypothesis.

Recognise business deception without trusting appearances

Typosquatting uses a lookalike or easily mistyped domain to create a misleading impression. Shortened URLs can conceal their destination; they are not inherently malicious, but they remove useful context. Examine destinations through approved analysis tools rather than opening suspicious links in a normal session. Compare the actual address and domain with trusted business records, not only the display name.

Business email compromise may involve a spoofed sender or a genuinely compromised mailbox. A message requesting an unusual payment or changed bank details needs verification through an established independent channel. Email authentication results help assess sending-domain claims but do not prove the business request is legitimate. Inspect relevant headers, mailbox rules, sign-in history, and sent-message patterns while preserving the original message.

Keep these points in mind

  • Impossible travel requires session and network context.
  • Cloud audit events may explain activity invisible to endpoint tools.
  • Authenticated email can still carry a fraudulent request.

Pause and practise

A familiar supplier’s mailbox passes authentication checks but asks for a new payment destination. What should triage do next?

Show a worked response

Pause the requested change and verify it using a previously established supplier contact. Preserve the email and inspect the account’s sign-ins, rules, and recent messages if authorised. Passing authentication supports the sending-domain identity; it does not establish that the supplier intended the instruction or that the mailbox remains under legitimate control.

← Previous lesson