TL;DR: SIEM and ITDR platforms miss slow-moving identity attacks when the evidence needed to connect events sits outside practical query windows, even though credentials remain the leading initial access vector in breaches and cloud dwell time still stretches for months, according to 8Layers. Detection has become a history problem, not a rule-count problem.
At a glance
What this is: 8Layers says identity detection breaks down when platforms cannot correlate signals across long time spans, leaving dormant identities and slow campaigns effectively invisible.
Why it matters: This matters because IAM, NHI, and ITDR programmes need historical context to detect abuse that unfolds over months, not just alerts that match same-day activity.
By the numbers:
- NHI are growing 40x faster than humans, according to 8Layers.
- Credentials were involved in 38% of all incidents analyzed by Verizon's 2024 DBIR, according to 8Layers.
- The average time to detect a cloud breach in 2025 was 219 days, according to CSA Lab Space research cited by 8Layers.
- For every human identity in an organization there are on average 92 non-human identities, according to Entro Labs' 2025 research cited by 8Layers.
Context
Identity detection becomes unreliable when platforms can see recent activity but not the earlier events that give that activity meaning. In this article, 8Layers argues that the core problem is not a lack of alerts, but a lack of historical identity context that can be correlated across long periods.
That gap matters most for NHI and identity threat detection and response, where service accounts, OAuth applications, API keys, and AI agents often remain dormant before being reused. If the platform cannot connect creation, idle periods, and later activation, it cannot reconstruct the attack chain or distinguish benign noise from meaningful identity abuse.
Key questions
Q: What breaks when identity detections cannot look back far enough?
A: The ability to connect provisioning, dormancy, and later misuse breaks down. Teams may still see the later event, but they lose the earlier identity context that proves it is part of the same attack chain. That leads to fragmented investigations, missed causality, and false confidence in detection coverage.
Q: Why do dormant service accounts and OAuth applications increase detection risk?
A: They create a long gap between identity creation and identity abuse, which is exactly where many analytics platforms lose correlation. If a platform cannot join the original issuance event to the later activation or misuse, the identity looks ordinary at the moment of abuse and the attack blends into baseline activity.
Q: How do you know if identity threat detection is actually working?
A: Look for shorter mean time to detect and mean time to respond, plus fewer incidents where suspicious sessions persist for hours. Successful programmes also show accurate correlation between behavioural anomalies and real misuse, not just alert volume. If detection cannot trigger containment before damage spreads, the programme is still mostly observational.
Q: What should teams prioritise: more detections or longer identity history?
A: Longer identity history, when the objective is to detect slow campaigns and dormant account abuse. More rules improve signal volume, but they do not create the earlier context needed to explain why a later event matters. Without that history, the platform can still alert, but it cannot reliably correlate.
Technical breakdown
Why detection windows break identity correlation
SIEM and analytics platforms are optimised for query performance over recent data, not for continuously linking events separated by months. That creates a structural gap: the earlier identity signal may still exist, but it sits in colder storage or outside the practical query horizon, so the platform cannot combine it with the later event that makes it relevant. In identity terms, the problem is not event absence. It is event separation across storage tiers, cost boundaries, and time windows that prevent causal correlation.
Practical implication: treat query horizon as a detection control boundary, not a tuning detail.
Why more rules do not solve historical context loss
Rule volume can improve coverage for single events, but it cannot recreate missing context. A credential-abuse rule firing today cannot ingest a risk signal from six months ago if that prior signal is inaccessible or too expensive to query at detection time. That is why more detections often increase noise without improving causality. The hard limitation is architectural: if the platform cannot hold and join identity history over time, no rule can infer the relationship on its own.
Practical implication: evaluate whether your detections can join old and new identity events before adding more rules.
How dormant NHIs create delayed attack chains
Non-human identities change the problem because they are frequently created for a single project, left dormant, and later reactivated. That behaviour creates a delayed attack chain in which the creation event and the misuse event are causally linked, but not temporally adjacent. Service accounts, OAuth applications, API keys, and AI agent identities all fit this pattern. If the detection engine does not preserve the full lifecycle context, it will miss the transition from harmless provisioning to malicious activation.
Practical implication: build detection logic around identity lifecycle continuity, not only live-session activity.
Threat narrative
Attacker objective: The attacker aims to reuse dormant identity trust to move through the environment without detection until the abuse chain is complete.
- Entry begins when a dormant identity such as an OAuth application, service account, or API key is created and left unused for a long period.
- Escalation occurs when that identity is reactivated or abused months later, while the earlier provisioning context remains outside the platform's practical detection window.
- Impact follows when the platform fails to connect the old creation event with the new use event, allowing the attacker to blend into routine identity activity.
Breaches seen in the wild
- Sumo Logic breach 2023: A compromised credential opened a Sumo Logic AWS account; customers were told to rotate API keys and stored credentials. No data impact was found.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Historical identity context has become a control plane, not a forensic luxury. The article's core point is that detection fails when the platform cannot correlate identity events across time, storage tiers, and query costs. That means the real control boundary is no longer the alert rule itself, but the history available to the rule. Practitioners should treat long-horizon correlation as part of the identity programme's architecture, not an optional analytics feature.
Identity detection is now constrained by retention economics as much as by logic. The article shows that better rules do not help when the underlying data sits outside the practical query window. That is a governance problem because teams often assume detection depth scales with product maturity, when in reality it is capped by storage design and cost tolerance. The implication is that security leaders need to measure how far back identity context can be joined, not how many detections are shipped.
Dormant NHI create identity blast radius across time. Service accounts, OAuth applications, API keys, and AI agents do not follow human work patterns, so their creation and reactivation can be separated by months. That creates a distinct governance concept: the temporal distance between identity issuance and identity misuse. The longer that distance, the easier it is for attack chains to hide in plain sight. Practitioners should manage identity lifecycle continuity as a detection requirement, not only an administrative one.
ITDR programmes must shift from event detection to story reconstruction. The article argues that isolated alerts are easy; the hard part is proving that multiple low-signal events belong to the same attack. That means the differentiator is no longer single-signal precision but the ability to reconstruct causality across the full identity history. For identity teams, this changes how tooling should be evaluated and how incidents should be triaged.
What this signals
Temporal correlation is now a governance requirement for ITDR. Teams that only tune detections for recent activity will continue to miss campaigns that rely on dormant identities and delayed reactivation. The practical test is whether investigators can reconstruct a full identity story without leaving the platform.
Identity blast radius is measured in time as well as privilege. A service account or OAuth application that sits unused for months can become more dangerous, not less, because the original creation context decays while the credential remains valid. Security leaders should treat lifecycle visibility as a first-order control objective.
Historical joinability should be part of platform evaluation. If a detection stack cannot connect old identity events to present activity at reasonable cost, then the gap is architectural, not operational. That means buyers need to ask how far back correlation can reach before they trust the result.
For practitioners
- Audit your detection horizon Measure how far back your platform can correlate identity events without manual export or expensive one-off queries. Record the actual join window for human identities, NHI, and dormant accounts.
- Map dormant identity lifecycle paths Inventory service accounts, OAuth applications, API keys, and AI agent identities that can sit idle before reuse. Flag those whose creation and later activation would not be visible in the same investigation timeline.
- Test cross-period correlation scenarios Simulate a benign provisioning event followed months later by suspicious use and confirm whether the platform reconstructs both events as one chain.
- Separate rule coverage from historical context Review detection engineering goals to distinguish between alerts that catch same-day behaviour and analytics that explain why a later event matters because of older identity history.
Key takeaways
- Identity detection fails when the platform cannot connect older identity events with later misuse.
- The article's central warning is architectural, not tactical: detection windows can hide dormant account abuse and slow campaigns.
- Practitioners should test whether their tools preserve enough identity history to reconstruct attacks end to end.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-09 — NHI Reuse | Dormant identities are reused long after their original context fades from detection. |
| NHI-01 — Improper Offboarding | Abandoned service accounts and OAuth apps remain reachable long after they should be retired. | |
| Recommendation — Track NHI reuse across creation and reactivation events to preserve investigation context. Review offboarding controls for NHIs that linger after their intended project ends. | ||
| NIST CSF 2.0 | DE.CM-01 — Monitoring for Anomalies and Events | The article is about monitoring limitations and historical correlation gaps. |
| PR.AA-05 — Access Permissions, Entitlements and Authorizations | Credential abuse follows from poorly governed identity permissions over time. | |
| Recommendation — Extend anomaly monitoring so identity events can be correlated across long retention windows. Revalidate entitlements for dormant identities before they re-enter active use. | ||
| MITRE ATT&CK | TA0006;TA0008 — Credential Access; Lateral Movement | The article centers on credential-driven intrusion paths that unfold over time. |
| Recommendation — Map delayed identity abuse to credential access and lateral movement patterns in detection content. | ||
Key terms
- Detection Horizon: The detection horizon is the period of history a security platform can practically query and correlate when investigating identity activity. In identity governance and ITDR, it determines whether earlier provisioning events can still be linked to later misuse or whether the attack is fragmented by storage and cost boundaries.
- Temporal Correlation: Temporal correlation connects events because of when they occur relative to one another. In security operations, a sequence such as failed logins followed by a successful login can indicate a coordinated attack pattern. This helps analysts interpret event order as evidence of intent rather than isolated noise.
- Dormant Identity: A non-human identity that is no longer actively used but still has valid access. Dormancy is risky because it looks harmless while preserving credentials, permissions, and trust relationships that can still be abused or accidentally triggered.
- Identity Blast Radius: The amount of damage a compromised identity can cause across systems, data, and infrastructure. In NHI environments, it is shaped by permissions, network reach, and administrative capability rather than by the credential alone. Reducing blast radius is a containment strategy that limits lateral movement and data exposure.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org