Join our Newsletter — 33% off our NHI Course

What are the signs that stolen credentials are being used for stealthy internal discovery?

Common signs include login activity from unfamiliar virtual machines, use of internal VPN addresses from suspicious sources, repeated LDAP queries, and broad service discovery across multiple hosts. These behaviors often indicate an attacker is mapping the environment, collecting user and trust data, and preparing for further access while trying to look like normal internal traffic.

What internal discovery looks like after stolen credentials are in play

The key clue is not just that a login succeeded, but that the session starts behaving like an explorer. stolen credentials are often used to blend into normal internal traffic while an attacker enumerates directories, queries identity stores, tests service reachability, and samples trust relationships. That makes the pattern noisy in small ways, but unusually broad in scope.

One of the clearest signals is a successful sign-in from an unfamiliar virtual machine or VPN source that then behaves like an internal admin or analyst account. In practice, that means the login origin, timing, and follow-on activity do not match the person or system that normally uses the credential. A linkable example of this pattern is SonicWall SSL VPN account compromises 2025, where valid credentials were used to access many VPN accounts and move laterally.

Repeated LDAP activity is another strong indicator because it often reflects directory enumeration rather than ordinary application use. Attackers use those queries to identify users, groups, service accounts, trusts, and useful naming patterns, then widen the search to adjacent hosts and systems. When that pattern appears alongside broad service discovery, it usually means the credential is being used for mapping and access expansion, not for one-off work.

Why these behaviors stand out from normal internal use

Normal internal activity tends to be narrow, repeatable, and tied to a known role. Stealthy discovery is broader and more adaptive. The account may touch many hosts in a short time, query attributes it has never needed before, and probe services that do not fit the user’s everyday workflow. That shift from task execution to environment reconnaissance is what makes the behavior suspicious.

Discovery also tends to reveal itself through access path inconsistencies. For example, an internal VPN address may appear, but the device posture, geolocation, host fingerprint, or login cadence does not fit the expected user pattern. Those inconsistencies matter because they show the credential is valid, but the actor behind it is not the normal operator of that identity. The question is not whether the login is technically successful, but whether the downstream activity makes sense for the account’s normal purpose.

For readers wanting the broader identity angle, Ultimate Guide to NHIs, Key Challenges and Risks covers why visibility gaps and unmanaged credentials create the conditions for this kind of hidden follow-on activity, even though the discovery pattern itself is not unique to any one identity type.

What the attacker is usually trying to learn

Once inside, the attacker is typically collecting enough structure to decide where to go next. LDAP queries help reveal who has privileged access, how groups are nested, where trust relationships exist, and which systems may be easier to reach. Broad service discovery across hosts helps identify file shares, admin interfaces, remote management tools, and other services that can be abused for persistence or lateral movement.

That is why these signals are so important as a cluster. Any one event may be explainable, but the combination of unfamiliar source, directory probing, and host-wide discovery points to an adversary trying to reduce uncertainty before the next stage of compromise. A useful defensive reference point is The 52 NHI Breaches Report, which shows how stolen credentials often become the entry point for broader access and later movement.

Risk and Threat Considerations

Stolen credentials used for stealthy discovery are dangerous because they can look legitimate for long enough to avoid immediate containment. The risk is not limited to the original account, because reconnaissance often exposes additional users, services, and trust paths that an attacker can abuse next.

Failure mechanism: A valid login is followed by unusually broad enumeration, directory querying, and service probing that mimics internal activity while building a map of the environment for later abuse.

Impact: The attacker can identify privileged paths, expand access, and prepare lateral movement or persistence before defenders recognise that the credential is compromised.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
MITRE ATT&CK T1087 — Account Discovery LDAP-style enumeration directly matches account and directory discovery after valid access.
T1046 — Network Service Discovery Broad service discovery across multiple hosts is a core post-compromise discovery behavior.
T1021 — Remote Services Suspicious internal VPN and remote access usage often precede discovery and lateral access.
Recommendation — Detect and hunt for account discovery activity following suspicious logins. Alert on unusual service probing across many internal hosts. Correlate remote access sessions with subsequent discovery and movement.
NIST SP 800-53 Rev 5 AU-6 — Audit Record Review, Analysis, and Reporting Suspicious logins and discovery patterns require review of correlated audit data.
IA-2 — Identification and Authentication (Organizational Users) The scenario depends on compromised or abused user authentication.
AC-6 — Least Privilege Discovery becomes more dangerous when stolen credentials can enumerate broadly.
Recommendation — Correlate authentication, directory, and host logs to confirm suspicious discovery. Strengthen user authentication and monitor for abnormal authenticated sessions. Limit account scope so stolen credentials cannot query or reach unnecessary assets.
OWASP Non-Human Identity Top 10 NHI-05 — Overprivileged NHI Broad discovery is amplified when compromised credentials have excess internal reach.
NHI-07 — Long-Lived Secrets Credential theft is more consequential when secrets remain valid long enough for stealthy discovery.
Recommendation — Reduce privilege so stolen credentials cannot enumerate beyond their role. Shorten secret lifetime and revoke exposed credentials quickly.

Practitioner Guidance

What to prioritise: Treat the combination of successful login plus discovery behavior as higher risk than either signal alone. A single unusual source may be benign, but a valid session that starts querying LDAP broadly or touching many hosts should be investigated as probable reconnaissance.

What to verify: Check whether the source system, user agent, VPN path, and time-of-day are consistent with the account’s normal use. Then compare the commands and queries against historical baselines so you can separate real admin work from fast environment mapping.

Decision rule: If the credential can reach internal systems and the session is enumerating users, groups, or services outside its usual scope, prioritise containment and credential rotation before assuming the activity is merely anomalous but harmless.

Practitioner takeaway: Stealthy discovery is often the point at which a stolen credential stops being a single-access event and becomes an enterprise-wide risk, so the best response is to judge the session by its behavior after login, not by the fact that authentication succeeded.