SIEM
Impossible Travel Is Noisy. Watch Tokens and MFA Fatigue
VPN hops look like travel. Stream token reuse, refresh anomalies, and MFA push-spam into your SIEM so analysts can actually act.
Why “impossible travel” burns out the SOC
A laptop on VPN, then LTE, then a coffee-shop proxy can look like two countries in ten minutes. Coarse IP geolocation floods the queue. Real account takeovers hide in the noise.
You still want location as a hint. You cannot run identity threat detection on that signal alone. You need what happened to the session: tokens, device, MFA prompts.
Stolen tokens look like a normal user
Adversary-in-the-middle kits proxy the login and walk away with cookies or OAuth refresh tokens. After that, MFA does not help. The IdP sees a valid bearer token.
Watch the token, not just the password. User-agent flips, odd refresh patterns, and sudden scope jumps are the tells. AuthOne can stream those events so you revoke the family before the attacker moves laterally.
MFA fatigue is a velocity problem, not a one-off prompt
Push-spam works because platforms treat each tap as an isolated yes/no. Twenty prompts in two minutes is an attack, even if the user eventually approves.
Cap prompt rate. Fall back to a hardware key or number matching. Emit a structured event so the SIEM can page someone — not just log “MFA success.”
Ship identity events in seconds, then auto-revoke
Nightly log dumps are too slow once a session is stolen. Stream issuance, refresh, step-up, and failures into OpenTelemetry or your SIEM as they happen.
When detections fire, call AuthOne to kill refresh tokens and force re-auth across apps. Mean time to respond should be a playbook, not a ticket to find the right admin console.
Related
Need help with identity or security architecture?
Talk to us