NEONIX SECURITY FABRICEXPOSURE / APPLICATION / IDENTITY
Security research

Research note · Identity threats

Identity threats

How attackers target identities, and the controls that limit what a stolen identity can do.

Type
Overview and practical guidance
Related products
CybrIdentity

Overview

Attackers increasingly log in rather than break in. A valid identity is quiet and fast, and often leaves little trace, which is why identity has become the main way into many environments.

The identity estate now includes more than employees: service accounts, machine and workload identities and AI agents all carry access.

Key concepts

  1. 01

    Credential theft and reuse

    Phishing, infostealer malware and passwords reused from earlier breaches give attackers working logins.

  2. 02

    Defeating MFA

    Prompt bombing, adversary-in-the-middle phishing and theft of session tokens can bypass weaker multi-factor methods. Phishing-resistant methods are stronger.

  3. 03

    Privilege abuse

    Attackers look for accounts with broad or standing privilege, and for permissions that accumulated over time.

  4. 04

    Non-human identities

    Service accounts and tokens often hold broad access, rarely rotate and are rarely reviewed, which makes them attractive.

What good looks like

  • Use phishing-resistant multi-factor authentication for privileged and remote access.
  • Remove standing privilege and use just-in-time access.
  • Run joiner, mover and leaver processes so access follows the person.
  • Review access regularly, including service and machine identities.
  • Monitor for unusual use of privileged accounts.

Common pitfalls

  • Treating MFA as a finished control.
  • Reviewing only human accounts.
  • Letting access accumulate across role changes.

How Neonix helps

CybrIdentity covers lifecycle, access reviews, entitlement and privileged access, and includes service, machine, workload and AI agent identities in the same view.

Identity analytics highlights orphaned, dormant and over-privileged accounts.

This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.