Because detection and containment are separate problems, and both can fail. Teams may discover suspicious activity late, but still need time to trace the identity, revoke access, and clean up connected accounts or sessions. Long dwell time means the attacker keeps a legitimate-looking path longer, which increases data loss, persistence, and the cost of recovery.
Why valid-credential breaches stay active for so long
When attackers already have valid credentials, they can blend into normal access paths instead of triggering obvious intrusion signals. That makes the problem less like “breaking in” and more like proving abuse, tracing what was touched, and then closing every path the credential opened. The delay is usually about detection quality, identity cleanup, and session control, not just attacker persistence.
What makes containment slower than detection
Detection can flag suspicious behavior, but containment still requires confidence about which identity was used, which systems it reached, and whether the attacker also copied tokens, cookies, API keys, or other secret material. If those dependencies are not mapped quickly, teams end up revoking access in stages, which extends dwell time. For credential-based incidents, identity tracing is often the bottleneck.
Longer dwell time is also common when access is distributed across SaaS, VPN, cloud consoles, service accounts, and delegated tools, because each system may keep its own session state. A password reset alone may not end access if refresh tokens, API keys, or cached sessions still work. The attacker can remain active until all linked credentials and sessions are identified and invalidated.
Why valid access is hard to distinguish from normal use
Valid credentials remove many of the usual attack signals, so defenders have to rely on context: device, location, timing, sequence of actions, privilege level, and unusual resource access. That is a harder problem than malware detection because the access itself may be legitimate. The attacker is abusing trust, not necessarily breaking a control in a visible way.
This is where identity governance and privileged access controls matter. If accounts are over-permissioned, shared, long-lived, or poorly inventoried, one credential compromise can open more systems than the team expects. Good hygiene shortens dwell time because it limits the blast radius and makes revocation more decisive.
Risk and Threat Considerations
Valid-credential breaches are attractive because they create stealth, persistence, and lateral movement opportunities while preserving a legitimate-looking access path. The longer a compromised account remains active, the more time an attacker has to harvest data, establish additional access, and pivot into higher-value systems.
Failure mechanism: Detection may identify suspicious use, but the real containment failure is incomplete identity tracing, weak session revocation, or lingering access through synced tokens, delegated credentials, and connected accounts.
Impact: Dwell time grows, attacker actions look normal for longer, and recovery becomes more expensive because teams must investigate every system the identity could reach before they can safely close the incident.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST SP 800-53 Rev 5 and OWASP ASVS set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 — Improper Offboarding | Compromised valid creds stay active when offboarding and revocation are incomplete. |
| NHI-02 — Secret Leakage | Stolen secrets and tokens often keep breaches active after initial discovery. | |
| NHI-07 — Long-Lived Secrets | Long-lived credentials extend attacker dwell time and delay containment. | |
| Recommendation — Revoke every live credential, token, and session when an identity is suspected compromised. Scan for leaked secrets and rotate any credential that could still authenticate. Replace long-lived credentials with short-lived, tightly scoped alternatives. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Dwell time depends on how quickly authenticators and tokens can be revoked. |
| AC-2 — Account Management | Account inventory and lifecycle control determine how fast abuse can be shut down. | |
| Recommendation — Enforce rapid credential rotation, revocation, and expiration for compromised authenticators. Maintain complete account inventories and disable compromised accounts without delay. | ||
| MITRE ATT&CK | T1078 — Valid Accounts | Valid accounts are the core mechanism that lets intruders blend in and persist. |
| T1110 — Brute Force | Credential abuse often follows theft, reuse, or guessing of valid access. | |
| Recommendation — Hunt for suspicious use of valid accounts and correlate it with abnormal access patterns. Monitor authentication events for repeated failures, success after failure, and impossible travel patterns. | ||
| OWASP ASVS | V7 — Session Management | Active sessions can outlive password changes and extend compromise windows. |
| V8 — Authorization | Overbroad authorization increases the damage and longevity of valid-credential abuse. | |
| Recommendation — Require session invalidation and token revocation when suspicious access is confirmed. Verify that access is least privilege and that privileged actions are separately controlled. | ||
Practitioner Guidance
What to verify: Confirm whether the compromised credential authenticated directly, through SSO, or through a chained secret such as a token or API key. If you cannot name every live session and downstream account the identity can still reach, containment is incomplete.
Decision rule: If the credential can authenticate to production, prioritise revocation of the access path and session invalidation before deep forensic cleanup. If the account is privileged or shared, treat the incident as a blast-radius problem first, and a single-account problem second.
What practitioners underestimate: Resetting the password is often only the first step. The true work is discovering whether the attacker also obtained bearer tokens, refresh tokens, trusted device sessions, or service-to-service credentials that survive the password change.
Practitioner takeaway: The longest valid-credential breaches are usually long because identity cleanup is harder than initial detection, so the winning move is to inventory every surviving access path and remove trust as quickly as possible.