TL;DR: SIEM and ITDR platforms miss slow-moving identity attacks when the evidence needed to connect events sits outside practical query windows, even though credentials remain the leading initial access vector in breaches and cloud dwell time still stretches for months, according to 8Layers. Detection has become a history problem, not a rule-count problem.
Editorial analysis by NHI Mgmt Group, based on content published by 8Layers: “Why Your Identity Telemetry Has Already Forgotten the Attack (and how an ITDR can solve it)”.
By the numbers:
- NHI are growing 40x faster than humans, according to 8Layers.
- Credentials were involved in 38% of all incidents analyzed by Verizon's 2024 DBIR, according to 8Layers.
- The average time to detect a cloud breach in 2025 was 219 days, according to CSA Lab Space research cited by 8Layers.
Key questions
Q: What breaks when identity detections cannot look back far enough?
A: The ability to connect provisioning, dormancy, and later misuse breaks down.
Q: Why do dormant service accounts and OAuth applications increase detection risk?
A: They create a long gap between identity creation and identity abuse, which is exactly where many analytics platforms lose correlation.
Q: How do you know if identity threat detection is actually working?
A: Look for shorter mean time to detect and mean time to respond, plus fewer incidents where suspicious sessions persist for hours.
Practitioner guidance
- Audit your detection horizon Measure how far back your platform can correlate identity events without manual export or expensive one-off queries.
- Map dormant identity lifecycle paths Inventory service accounts, OAuth applications, API keys, and AI agent identities that can sit idle before reuse.
- Test cross-period correlation scenarios Simulate a benign provisioning event followed months later by suspicious use and confirm whether the platform reconstructs both events as one chain.
Bottom line: Identity detection fails when the platform cannot connect older identity events with later misuse.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Historical identity context has become a control plane, not a forensic luxury. The article's core point is that detection fails when the platform cannot correlate identity events across time, storage tiers, and query costs. That means the real control boundary is no longer the alert rule itself, but the history available to the rule. Practitioners should treat long-horizon correlation as part of the identity programme's architecture, not an optional analytics feature.
A question worth separating out:
Q: What should teams prioritise: more detections or longer identity history?
A: Longer identity history, when the objective is to detect slow campaigns and dormant account abuse. More rules improve signal volume, but they do not create the earlier context needed to explain why a later event matters. Without that history, the platform can still alert, but it cannot reliably correlate.
👉 Read our full editorial: Identity detection fails when context falls outside the window