The answer is behavioral, and specific: per-identity behavioral. What does this account normally access? From which network? At what time of day? With what pattern of application use? An attacker holding a stolen session token for six weeks and then moving laterally looks different from the account's normal pattern. But only if you have a model of what normal looks like for that specific identity.
Hopkins describes the detection layer in terms of behavioral signals—source network, cloud VPC endpoint, network of origin—that reflect how a credential is being used, not just that it's being used. As attacker sophistication increases, from commodity actors operating from a different geography, to advanced actors using the same cloud infrastructure in a different VPC, to nation-state actors with an established foothold inside the network, behavioral context scales across all three. The signal doesn't get louder. It gets more precise.
Jesus Garcia, Abnormal AI's Solutions Architect, has watched this play out in deployments across industries. His read from the field: "Stop looking at identity as a login event. We need to implement additional controls that evaluate what happens before the sign-in, during the sign-in, and after the sign-in. And if you don't have a baseline of good behavior, you're not going to be able to identify account takeovers."
Breaches involving stolen or compromised credentials cost organizations an average of $4.67 million per incident and take an average of 186 days to identify and 60 to contain—the longest of any attack vector studied. (IBM)
Leach lands the same conclusion: "AI-powered behavioral analysis to detect anomalous activity, I would submit, is the key going forward to solving the post-authentication identity security problem."
The tools designed for the perimeter era were never built to model what a specific identity normally does after it authenticates. That's the capability gap. And it's the one most organizations still haven't closed.
