Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Enrichment baselines and NHI abuse: are your controls keeping up?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Enrichment baselines outperform static rules for spotting anomalous account and NHI behaviour, especially when attackers replay stolen tokens, shift IPs, or abuse Okta and SWA access patterns that threshold-only detections miss, according to Panther. The practical lesson is that behavioural context, not isolated event counts, is becoming central to identity and access monitoring.

NHIMG editorial — based on content published by Panther: Enrichment Baselines: A Statistical Framework for Threat Detection

By the numbers:

Questions worth separating out

Q: How should security teams detect identity compromise after authentication?

A: They should monitor what each identity actually does after login, including privilege use, command patterns, unusual data access, and cross-system movement.

Q: Why do static rules miss many NHI and account-abuse cases?

A: Static rules only fire when a single event is unusual enough on its own.

Q: What signals show that an identity is operating outside its normal boundary?

A: Look for sudden increases in authentication volume, rapid changes in country or IP diversity, unusual device patterns, and activity that appears at off-hours relative to the identity’s baseline.

Practitioner guidance

  • Baseline identities by behaviour, not just by account type Build 90-day behavioural profiles for users, admins, service accounts, and high-value NHI credentials across country, IP, device, and timing signals.
  • Correlate multiple weak signals into one identity story Combine volume spikes, IP diversity, geography shifts, and off-hours access into a single detection hypothesis instead of treating them as unrelated alerts.
  • Exclude recent activity from baseline training windows Keep the most recent seven days out of baseline construction so an ongoing compromise does not contaminate the reference profile.

What's in the full article

Panther's full blog covers the operational detail this post intentionally leaves for the source:

  • The exact baseline builder structure for Okta event history and the 90-day lookback window
  • Example z-score logic for IP diversity, country diversity, and hourly authentication volume
  • Detection patterns for Okta AD Agent token theft, Skeleton Key-style policy weakening, and SWA credential abuse
  • How the baseline excludes the most recent seven days so active attacks do not contaminate the reference profile

👉 Read Panther's analysis of enrichment baselines for threat detection →

Enrichment baselines and NHI abuse: are your controls keeping up?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

Enrichment baselines should be treated as an identity control, not only a detection engineering technique. The article shows that the real unit of risk is not the alert, but the behaviour of the identity behind it. That matters for IAM and NHI programmes because the same statistical approach can surface compromised service accounts, admin sessions, and AI-assisted abuse paths that threshold-based monitoring misses. Practitioners should treat behavioural baselining as part of access governance, not just SOC tuning.

A question worth separating out:

Q: How should teams use AI triage in anomaly detection workflows?

A: Use AI to summarise and prioritise the alert once the baseline has identified unusual activity. AI should help tell the story of what changed, not decide whether a weak control is acceptable. That keeps the statistical signal authoritative while reducing the time analysts spend reconstructing events.

👉 Read our full editorial: Enrichment baselines expose why static detections miss NHI abuse



   
ReplyQuote
Share: