TL;DR: Cross-domain attacks increasingly blend endpoint, identity, and cloud activity, and CrowdStrike says 75% of intrusions now begin without malware while adversaries use stolen credentials, service accounts, and legitimate tools to move quietly across environments. The governance problem is no longer isolated detection; it is identity blast radius control across domains.
At a glance
What this is: This is CrowdStrike’s analysis of cross-domain attacks that pivot across endpoint, identity, and cloud systems, showing how adversaries use legitimate access and tools to evade siloed detection.
Why it matters: It matters because IAM, PAM, and NHI controls are only effective when they constrain identity movement across domains, not just inside one control plane.
By the numbers:
- 75% of intrusions begin without malware, according to CrowdStrike's analysis of adversary activity.
Context
Cross-domain attacks are intrusions that move across endpoint, identity, and cloud environments rather than staying inside one security silo. In this article, CrowdStrike argues that those attacks are succeeding because organisations still govern access, detection, and response as separate problems instead of one identity-driven attack path.
The practical issue for IAM and NHI teams is that legitimate credentials can become the transport layer for lateral movement. When service accounts, compromised users, and administrative tools are treated as isolated controls rather than connected trust relationships, the attack path becomes harder to see and easier to extend.
CrowdStrike's example shows how a single intrusion can begin in one domain and then spread through ordinary access paths, which is typical of modern cross-domain tradecraft rather than an edge case.
Key questions
Q: What breaks when attackers can move across endpoint, identity, and cloud with valid credentials?
A: Siloed controls break because each domain may look normal on its own while the combined path shows compromise. Teams lose visibility into how one identity can traverse multiple systems, so lateral movement becomes easier to miss and harder to contain. The failure is not a single missed alert, but the absence of a shared trust boundary across domains.
Q: Why do stolen credentials and service accounts make cross-domain attacks harder to detect?
A: Because those identities can behave like legitimate administration traffic while still serving attacker objectives. When service accounts, remote tools, and admin sessions are allowed to blend into ordinary operations, signature-based detection and domain-by-domain monitoring lose context. The result is a longer dwell time and a larger opportunity for privilege escalation.
Q: What are the signs that identity blast radius is too large?
A: A large blast radius shows up when one account can reach multiple platforms, remote tools can cross trust boundaries, and administrators can pivot without separate approvals or segmentation. If a compromise in one domain quickly creates usable access in another, the identity architecture is too permissive for cross-domain threat conditions.
Q: How should security teams compare unified detection with point controls for cross-domain attacks?
A: Unified detection is better when the threat moves through several systems in one chain, because the attack only becomes visible when endpoint, identity, and cloud signals are combined. Point controls still matter, but they are insufficient if teams cannot reconstruct the full path of identity reuse and lateral movement.
Technical breakdown
How cross-domain attacks use legitimate identity paths
Cross-domain attacks rely on the fact that once an attacker has valid access, they can often move through systems using normal identity and administration channels. That means remote access, service accounts, privileged groups, and cloud sessions become part of the attack path rather than separate control domains. The problem is not only authentication failure. It is that identity trust is reused across endpoint, identity, and cloud layers without a unified view of where one account's access ends and another's begins.
Practical implication: map which identities can traverse more than one domain and treat that as a single blast-radius problem.
Why malware-free intrusion changes the control model
When intrusion begins without malware, signature-based detection loses much of its value and defenders have less obvious telemetry to anchor on. CrowdStrike’s article ties this to stolen credentials and legitimate tools, which let adversaries blend into routine admin activity. In that model, the security question shifts from 'what malicious file did we see?' to 'which valid identity, tool, or session is behaving outside its normal trust boundary?' That is a different detection problem, and it requires correlating identity, endpoint, and cloud activity together.
Practical implication: prioritize correlation across identity, endpoint, and cloud telemetry instead of waiting for malware indicators.
Identity blast radius is the real cross-domain control
Identity blast radius is the amount of access an account can exercise once it is compromised or abused. In cross-domain attacks, that blast radius expands when service accounts, administrator groups, and remote tools are allowed to bridge systems without tight scope limits. The article’s core message is that defenders need to understand not just whether access exists, but how far that access can propagate across connected environments. The smaller the cross-domain blast radius, the less room attackers have to pivot and persist.
Practical implication: review cross-domain privilege paths and reduce the number of identities that can move laterally between platforms.
Threat narrative
Attacker objective: The objective is to expand a foothold into cross-domain administrative control, then exfiltrate data or stage ransomware for disruption.
- Entry occurs when adversaries gain access through an unmanaged VPN appliance vulnerable to CVE-2024-3400, giving them a foothold into the target environment.
- Credential access and internal movement follow as the attacker uses a service account over RDP and attempts to dump credentials for broader reach.
- Escalation continues through attempts to add compromised and adversary-created accounts to administrator groups, then to deploy proxy-tunneling and remote access tools.
- Impact is attempted through reconnaissance, ransomware preparation, and data archiving and exfiltration, although the article says those actions were blocked or contained.
Breaches seen in the wild
- Schneider Electric Jira breach 2024: Credentials linked to a Lumma infostealer infection gave Hellcat access to Schneider Electric's Jira; 40GB and 400,000 user rows claimed.
- Change Healthcare breach 2024: A stolen login on a Citrix portal without MFA led to ALPHV ransomware, a $22 million ransom and 192.7 million people affected.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Cross-domain attack defense has become an identity governance problem, not just a detection problem. Once adversaries can move from endpoint to identity to cloud using valid credentials and approved tools, the issue is no longer whether one stack saw an alert. The governance question is whether access paths were ever designed as a single trust fabric at all. Practitioners should treat identity movement across domains as the primary control boundary.
Identity blast radius is the better operating metric than isolated account risk. An account that is acceptable inside one platform can become dangerous when it can pivot into another through remote access, privileged groups, or shared administrative tooling. That means the unit of analysis is not the account in isolation, but the maximum cross-domain reach of that account. Security teams should reframe review processes around propagation potential, not just entitlement count.
Fragmented telemetry creates a delay advantage for the attacker. Cross-domain activity succeeds when endpoint, identity, and cloud signals are held in separate consoles, because defenders have to reconstruct the path after the fact. That is why correlation quality matters as much as alert quality. Practitioners should prioritise unified visibility across domains before adding more point detections.
Legitimate tools are now part of the adversary playbook. Remote access software, credential management paths, and administrative utilities can all be used to look normal while an intrusion progresses. The defensive assumption that malicious behaviour must look obviously malicious is no longer reliable. Security teams need to evaluate how much normal administration they are willing to allow an attacker to borrow if one identity is compromised.
What this signals
Identity blast radius is now a cross-domain design problem. If a service account can move from one environment to another without strong segmentation, then a single compromised identity can become an enterprise-wide event. Programmes that still treat endpoint, identity, and cloud as separate governance zones will keep underestimating how far one set of credentials can travel.
Unified visibility is not a reporting preference, it is the control that makes cross-domain movement measurable. Without correlated identity, endpoint, and cloud telemetry, defenders see fragments rather than the attack path, which slows containment and increases the chance that legitimate tools will be misread as routine administration.
For practitioners
- Define cross-domain trust boundaries Inventory which identities can move from endpoint to identity to cloud and document every allowed lateral path. Treat those paths as a single governance surface rather than separate controls.
- Reduce cross-domain privilege propagation Restrict service accounts and admin accounts that can authenticate across multiple environments, especially where remote access tooling can bridge domains.
- Correlate identity and endpoint telemetry Join sign-in, privilege, remote access, and cloud activity so that one compromised identity cannot hide behind normal-looking behaviour in separate tools.
- Test for malware-free intrusion paths Run detection exercises that assume credential theft, legitimate tooling, and rapid lateral movement rather than file-based payloads.
Key takeaways
- Cross-domain attacks turn legitimate identity paths into attacker infrastructure when access can traverse endpoint, identity, and cloud without unified governance.
- The article’s evidence points to malware-free intrusion, stolen credentials, and service-account abuse as the main ingredients of modern lateral movement.
- Reducing identity blast radius and correlating telemetry across domains are the controls that change outcomes, not just adding more point detections.
Key terms
- Cross-domain attack: An attack that moves across identity, endpoint, cloud, and application boundaries rather than staying in one control domain. It succeeds when defenders treat those layers separately and allow a compromised identity or session to carry trust from one environment into another.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
- Malware-Free Intrusion: A compromise path that does not rely on dropping obvious malicious software. Attackers instead use valid credentials, trusted integrations, or legitimate cloud and SaaS activity, which shifts detection away from signatures and toward identity, behaviour, and access-pattern analysis.
- Lateral Movement: A post-compromise technique where an attacker uses a compromised NHI to move through a network, accessing additional systems and escalating impact without triggering detection.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
Published by the NHIMG editorial team on May 26, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org