Overview
Attackers increasingly log in rather than break in. A valid identity is quiet and fast, and often leaves little trace, which is why identity has become the main way into many environments.
The identity estate now includes more than employees: service accounts, machine and workload identities and AI agents all carry access.
Key concepts
- 01
Credential theft and reuse
Phishing, infostealer malware and passwords reused from earlier breaches give attackers working logins.
- 02
Defeating MFA
Prompt bombing, adversary-in-the-middle phishing and theft of session tokens can bypass weaker multi-factor methods. Phishing-resistant methods are stronger.
- 03
Privilege abuse
Attackers look for accounts with broad or standing privilege, and for permissions that accumulated over time.
- 04
Non-human identities
Service accounts and tokens often hold broad access, rarely rotate and are rarely reviewed, which makes them attractive.
What good looks like
- Use phishing-resistant multi-factor authentication for privileged and remote access.
- Remove standing privilege and use just-in-time access.
- Run joiner, mover and leaver processes so access follows the person.
- Review access regularly, including service and machine identities.
- Monitor for unusual use of privileged accounts.
Common pitfalls
- Treating MFA as a finished control.
- Reviewing only human accounts.
- Letting access accumulate across role changes.
How Neonix helps
CybrIdentity covers lifecycle, access reviews, entitlement and privileged access, and includes service, machine, workload and AI agent identities in the same view.
Identity analytics highlights orphaned, dormant and over-privileged accounts.
This note is an overview of the topic and of how Neonix approaches it. It does not report original incident data.