Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

All playbooks

SOC · SOC analysts and identity teams

Suspicious sign-in investigation

Correlate authentication, session and account-change evidence.

An unusual sign-in is a question about identity, session and follow-on activity, not a compromise verdict.

What this does not establish

  • New geography alone cannot distinguish a VPN from an intruder.
  • An MFA challenge does not prove the session was denied.
  • A successful sign-in does not show what the session accessed.

0 of 8 ticked

Selected step

FrameStep 1 of 8

Preserve the identity-provider record before aggregating.

Capture the full sign-in event

  • Keep account, result, application, client, source and session identifiers.
  • Normalize event time and record log delay.