Forensic identity analysis
Notes on identity,
and the last mile no one owns.
Forensic breakdowns of real identity incidents and notes on the operational reality of identity security — the gap between a deployed product and identity actually under control.
Latest
The MFA Coverage Audit: Finding the Doors Without Locks
"MFA is enabled" is not a posture statement. Coverage is. A working checklist for finding every door that can still authenticate without it — legacy protocols, service accounts, and the recovery paths that quietly undo everything.
Read the write-upMore writing
All posts →Fourteen Incidents, One Table: Where the Last Mile Broke
Fourteen identity breaches from this series in one table — the way in, what looked under control, the unowned work that actually failed, and who caught it. The pattern is hard to miss once they line up.
The Identity Control Map: What Each Control Covers, and Where It Doesn't
Controls aren't on/off. Each one covers a slice of the problem and leaves a residual that someone has to own. A map of the major identity controls, what they actually cover, and the exact gap where the last mile lives.
What AI Does to the 75/25 Split — and to Your Margin
AI is making the deployable part of identity nearly free. If that's what you bill for, your margin is evaporating. The money is moving to the part that doesn't automate.
Posture as a Continuous Process, Not a Quarterly Audit
The quarterly audit is a photograph of a moving river. Identity drifts daily; here's what it takes to operate posture as a loop instead of an event.
75/25: The Quarter That Won't Automate
AI is automating the productized three-quarters of identity work and barely touching the operational quarter — the one with no owner. It doesn't pave the last mile. It lengthens it.
Seven Posture Failure Modes Compliance Never Catches
Each of these passes a compliance audit and shows up green on a dashboard, and each one has put a real company in the headlines. The gap between 'defined' and 'holding.'
Build, Buy, or Framework: The Real Cost of Each Path for an MSSP
The sticker price is the smallest number in the decision. Here's the actual total cost of building, buying, or owning the process for identity at MSSP scale.
How to Measure Identity Posture When You Have 200 Clients and No Two Tenants Alike
A single posture checklist falls apart the moment you run it across hundreds of heterogeneous client tenants. Here's how to measure something comparable anyway.
The Economics of the Last Mile: The Margin MSSPs Give Away for Free
Most MSSPs price identity like a deployment and deliver it like an operation. The gap between those two is margin you're giving away — or risk you're leaving with the client.
ISPM Without the Marketing: Posture Is Not a Dashboard
Identity security posture is sold as a screen full of green checks. The screen is an input, not the posture. Here's the difference, and why it matters operationally.
The Last Mile of Identity: The Thesis
Identity systems get 'deployed' and still don't work, because the work that makes them work has no owner. The thesis, drawn from a decade of incidents.
The AI Tool You Connected and Forgot
Anatomy of an Identity Incident — Vercel, April 2026. An OAuth token an employee granted to an AI tool months earlier, sitting forgotten, became the way in after the AI vendor got infected.
Seven Hundred Breaches, One Stolen Integration
Anatomy of an Identity Incident — the Salesloft Drift campaign, 2025. The attackers didn't breach 700 companies. They breached one integration that already had the keys to all of them.
Two Years Later, the Same Phone Call
Anatomy of an Identity Incident — M&S and Co-op, 2025. The exact playbook that took down MGM in 2023, run again, against an outsourced service desk, for a few hundred million pounds.
The App You Authorized Yourself
Anatomy of an Identity Incident — the UNC6040 Salesforce campaign, 2025. No password was stolen and no token was cracked. An employee was talked into authorizing a malicious app, and the app did the rest.
Infostealers, and Why a Password You Changed Years Ago Can Still Burn You
Infostealer malware quietly harvests credentials and sessions from endpoints, and they circulate for years. Here is how the pipeline works and why enforced MFA is the control that defuses it.
It Wasn't a Vulnerability. It Was a Setting Left Off.
Anatomy of an Identity Incident — Snowflake, 2024. The platform was never breached. Around 165 customers were, because multi-factor authentication was optional and nobody made it mandatory.
Token Signing, and What "Token Forgery" Actually Means
Modern auth tokens are trusted because they're signed. Here is how signing works, what a signing key really is, and why stealing one means an attacker can mint valid identities at will.
The Test Account That Read the Executives' Email
Anatomy of an Identity Incident — Midnight Blizzard, January 2024. A forgotten test account with no MFA, and a forgotten app with too much access, were enough to reach senior leadership's inbox.
When the Vendor Is Breached but the Incident Is Yours
Anatomy of an Identity Incident #1 — Okta's support case system, October 2023. What broke at the identity layer, and who was actually responsible for catching it.
OAuth Tokens Explained: Why Changing Your Password Doesn't Kick the Attacker Out
OAuth is how you let one app access another without sharing a password. Here is what the tokens are, why they outlive your password, and why a connected app is its own standing identity.
A Phone Call Beat Every Control
Anatomy of an Identity Incident — MGM and Caesars, September 2023. No exploit, no malware. Someone called the help desk, and the help desk issued an identity to the wrong person.
Nothing Was Stolen. The Tokens Were Forged.
Anatomy of an Identity Incident — Storm-0558, 2023. A leaked signing key let an attacker mint valid identities for anyone. No password was guessed, because none was needed.
What Really Happens When the Help Desk Resets Your MFA
Account recovery is the one flow designed to grant access to someone who can't prove who they are. Here is what the reset actually does, and why it's the weakest point in your identity stack.
The Vault Was Only as Safe as a Home Computer
Anatomy of an Identity Incident — LastPass, 2022. The decryption keys to every customer's vault backups were reachable through one engineer's personal home PC.
SCIM Provisioning: How It Works and the Places It Silently Breaks
SCIM is how accounts get created and removed across your apps automatically. Here is the mechanism, and the failure modes that leave access lingering.
2FA Was On. The Session Walked Out Anyway.
Anatomy of an Identity Incident — CircleCI, January 2023. Malware lifted a 2FA-backed session off one laptop, and a CI platform's vault of customer secrets emptied out.
The Lifecycle of a Service Account Nobody Owns
Service accounts are created in a hurry and outlive everyone who remembers them. Here is the full lifecycle, and where it quietly goes wrong.
The Push Notification Was Never the Real Problem
Anatomy of an Identity Incident — Uber, September 2022. Everyone remembers the MFA fatigue. The breach that mattered happened one layer deeper, in a script no one owned.
Same Phish, Two Outcomes
Anatomy of an Identity Incident — the 0ktapus campaign, 2022. One phishing kit hit 130-plus companies. Why most got breached and at least one didn't comes down to a single control.
One-Time Codes vs. Passkeys: What "Phishing-Resistant" Actually Means
Not all multi-factor authentication is equal. Here is the mechanical reason a security key or passkey stops phishing that a six-digit code can't.
What's Inside a HAR File — and Why You Should Scrub It Before You Share It
Support asks for a HAR file and you upload one without thinking. Here is what's actually in it, why it can contain live credentials, and how to strip them first.
Your Vendor's Subcontractor Is Your Attack Surface
Anatomy of an Identity Incident — Okta and Sitel, January 2022. The breach happened on a support subcontractor's laptop. The blast radius was every customer tenant that laptop could reach.
How Session Tokens Actually Work (and Why MFA Can't Save a Stolen One)
A plain walkthrough of what a session token is, why it exists, and the reason multi-factor authentication does nothing once one has been stolen.
Series
Anatomy of an Identity Incident
Forensic write-ups of real public breaches, strictly at the identity layer. No vendor villains — just what broke, what would have caught it, and who was actually responsible.
15 postsThe Last Mile of Identity
Where identity actually breaks: the gap between a deployed product and identity under control, and why no one owns it.
2 postsHow It Works
Vendor-neutral explainers on the mechanics of identity — how the pieces actually work, and the places they quietly break. No products, no pitch.
9 postsWhat Posture Actually Means
Identity posture for the people who operate it, not the people who buy it — how to measure it, the failure modes compliance never catches, and why a dashboard isn't posture.
6 postsThe Economics of the Last Mile
The business side of identity for MSSPs — unit economics, where margin quietly leaks, and the real cost of build vs. buy vs. owning the process.
3 posts