Because many attacks now abuse valid access, mimic normal behaviour, and move across channels faster than manual review can keep up. Static signatures and isolated reviews are least effective when the attacker looks normal in each individual system but abnormal across the full sequence of activity.
Why Legacy Controls Miss Identity-Based Attacks
Legacy controls were built to catch bad code, bad binaries, or obviously malicious network behaviour. Identity-based attacks are different: they often reuse real credentials, operate through approved channels, and stay within normal-looking application or directory activity until the attack chain is already advanced.
That creates a visibility gap. A single login, token use, or admin action may look acceptable in isolation, even when the overall sequence shows theft, impersonation, privilege escalation, or lateral movement. Controls that do not correlate identity, session, and behavioural context across systems tend to miss exactly that pattern.
Modern attackers also exploit the fact that access is now highly distributed. The same identity can touch cloud consoles, SaaS, endpoints, APIs, and directory services, so a control tuned to one layer often cannot see abuse that starts elsewhere and finishes in another plane.
Why Signatures, Blocks, and Isolated Reviews Break Down
Static detection assumes the attacker has a stable indicator, but identity abuse is often adaptive. Valid accounts, token replay, password spraying, MFA fatigue, consent abuse, and session theft can all present as legitimate traffic unless the control is watching for context shifts, not just known indicators.
Isolated reviews fail for a different reason: they often treat each system as the unit of analysis. A directory event may look routine, an endpoint event may look minor, and a SaaS event may look normal, yet the combined chain reveals compromise. That is why identity-centric detection needs to understand sequences, privilege changes, and unusual access paths rather than only endpoint alerts or point-in-time exceptions.
Legacy controls also struggle with speed. Manual review is too slow when attackers can authenticate, enumerate, and move laterally in minutes. When the control loop depends on after-the-fact human inspection, the attacker has already used the session, the token, or the delegated permission before anyone compares notes.
What Modern Identity Defence Has to Correlate
Effective identity defence now has to connect authentication, authorization, session activity, and privilege transitions into one view. That is the difference between spotting a normal login and spotting a stolen identity being used to pivot across systems, impersonate a trusted user, or abuse access that was technically valid but operationally suspicious.
This is why identity-aware monitoring is often paired with Identity Threat Detection and Response (ITDR) Guide, which focuses on the attack techniques and response patterns that legacy tools miss. It is also why lifecycle controls matter, because stale access, long-lived credentials, and unclear ownership make it easier for attackers to blend in after initial compromise, as covered in the NHI Lifecycle Management Guide.
When the question is not just about identity but about broader attack pathways, the Top 10 NHI Issues is useful for understanding how access sprawl, overprivilege, reuse, and weak governance create durable exposure. The common theme is that modern defence has to understand who or what is acting, what authority it has, and whether the activity still makes sense across the full chain.
Risk and Threat Considerations
Identity-based attacks are dangerous because they convert trusted access into attacker cover. Once the adversary is using valid credentials or tokens, many perimeter and signature-based controls lose the visual cues they were designed to catch.
Failure mechanism: The control watches for known-bad artefacts or single-system anomalies, but the attacker uses approved identity material and distributes activity across systems, so no individual event looks decisive.
Impact: Compromise can persist longer, lateral movement becomes easier, and response is delayed until the attacker has already expanded reach or exfiltrated data.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | T1078 — Valid Accounts | Identity-based attacks often abuse legitimate accounts and sessions. |
| Recommendation — Map access anomalies to Valid Accounts and hunt for abuse across adjacent systems. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Cross-system identity abuse requires correlated audit analysis. |
| IA-5 — Authenticator Management | Long-lived credentials and token misuse are central to modern identity attacks. | |
| Recommendation — Correlate audit data across identity, endpoint, cloud, and application logs. Rotate, revoke, and tightly manage authenticators and credential lifecycles. | ||
| NIST CSF 2.0 | DE.CM-01 — Network and Environment Monitoring | Identity attacks require continuous monitoring across environments and channels. |
| Recommendation — Monitor identity activity continuously across environments and alert on sequence anomalies. | ||
| CIS Controls v8 | CIS-5 — Account Management | Stale, excessive, or unmanaged accounts widen identity attack paths. |
| Recommendation — Enforce account inventory, ownership, and timely disablement of unused access. | ||
Practitioner Guidance
What to verify: Check whether your control stack can correlate identity events across directory, cloud, SaaS, endpoint, and application layers. If each review only sees one system, the attacker can remain invisible while still using valid access.
Decision rule: If the suspicious action is performed through a real account, token, or delegated session, treat the problem as an identity-control failure first, not just an endpoint or malware problem. The key question is whether the access path itself should still have existed.
What good looks like: You should be able to trace a login, privilege change, and downstream use of access as one chain, with alerts that trigger on abnormal sequence, timing, scope, or cross-system movement rather than on a single bad signature.
Practitioner takeaway: Legacy controls fail when they are blind to valid but hostile use of access. The most reliable defence is not more isolated alerts, but tighter correlation between identity, privilege, session behaviour, and cross-system movement.
Related resources from NHI Mgmt Group
- Why do upstream gateways and signature based controls miss so many modern email and identity attacks?
- Why do legacy applications and siloed identity controls increase the risk of identity-based attacks in mixed environments?
- Why do identity-based attacks become harder to contain when organisations rely on legacy access controls?
- Why do browser-based applications need different identity controls than legacy SAML websites?