Forensic identity analysis

Notes on identity,
and the last mile no one owns.

Forensic breakdowns of real identity incidents and notes on the operational reality of identity security — the gap between a deployed product and identity actually under control.

Latest

What Posture Actually MeansJune 15, 2026

The MFA Coverage Audit: Finding the Doors Without Locks

"MFA is enabled" is not a posture statement. Coverage is. A working checklist for finding every door that can still authenticate without it — legacy protocols, service accounts, and the recovery paths that quietly undo everything.

Read the write-up

More writing

All posts →
Anatomy of an Identity IncidentJun 15, 2026

Fourteen Incidents, One Table: Where the Last Mile Broke

Fourteen identity breaches from this series in one table — the way in, what looked under control, the unowned work that actually failed, and who caught it. The pattern is hard to miss once they line up.

What Posture Actually MeansJun 15, 2026

The Identity Control Map: What Each Control Covers, and Where It Doesn't

Controls aren't on/off. Each one covers a slice of the problem and leaves a residual that someone has to own. A map of the major identity controls, what they actually cover, and the exact gap where the last mile lives.

The Economics of the Last MileJun 14, 2026

What AI Does to the 75/25 Split — and to Your Margin

AI is making the deployable part of identity nearly free. If that's what you bill for, your margin is evaporating. The money is moving to the part that doesn't automate.

What Posture Actually MeansJun 13, 2026

Posture as a Continuous Process, Not a Quarterly Audit

The quarterly audit is a photograph of a moving river. Identity drifts daily; here's what it takes to operate posture as a loop instead of an event.

The Last Mile of IdentityJun 12, 2026

75/25: The Quarter That Won't Automate

AI is automating the productized three-quarters of identity work and barely touching the operational quarter — the one with no owner. It doesn't pave the last mile. It lengthens it.

What Posture Actually MeansJun 9, 2026

Seven Posture Failure Modes Compliance Never Catches

Each of these passes a compliance audit and shows up green on a dashboard, and each one has put a real company in the headlines. The gap between 'defined' and 'holding.'

The Economics of the Last MileJun 6, 2026

Build, Buy, or Framework: The Real Cost of Each Path for an MSSP

The sticker price is the smallest number in the decision. Here's the actual total cost of building, buying, or owning the process for identity at MSSP scale.

What Posture Actually MeansJun 2, 2026

How to Measure Identity Posture When You Have 200 Clients and No Two Tenants Alike

A single posture checklist falls apart the moment you run it across hundreds of heterogeneous client tenants. Here's how to measure something comparable anyway.

The Economics of the Last MileMay 27, 2026

The Economics of the Last Mile: The Margin MSSPs Give Away for Free

Most MSSPs price identity like a deployment and deliver it like an operation. The gap between those two is margin you're giving away — or risk you're leaving with the client.

What Posture Actually MeansMay 20, 2026

ISPM Without the Marketing: Posture Is Not a Dashboard

Identity security posture is sold as a screen full of green checks. The screen is an input, not the posture. Here's the difference, and why it matters operationally.

The Last Mile of IdentityMay 15, 2026

The Last Mile of Identity: The Thesis

Identity systems get 'deployed' and still don't work, because the work that makes them work has no owner. The thesis, drawn from a decade of incidents.

Anatomy of an Identity IncidentApr 30, 2026

The AI Tool You Connected and Forgot

Anatomy of an Identity Incident — Vercel, April 2026. An OAuth token an employee granted to an AI tool months earlier, sitting forgotten, became the way in after the AI vendor got infected.

Anatomy of an Identity IncidentSep 15, 2025

Seven Hundred Breaches, One Stolen Integration

Anatomy of an Identity Incident — the Salesloft Drift campaign, 2025. The attackers didn't breach 700 companies. They breached one integration that already had the keys to all of them.

Anatomy of an Identity IncidentJul 15, 2025

Two Years Later, the Same Phone Call

Anatomy of an Identity Incident — M&S and Co-op, 2025. The exact playbook that took down MGM in 2023, run again, against an outsourced service desk, for a few hundred million pounds.

Anatomy of an Identity IncidentJun 25, 2025

The App You Authorized Yourself

Anatomy of an Identity Incident — the UNC6040 Salesforce campaign, 2025. No password was stolen and no token was cracked. An employee was talked into authorizing a malicious app, and the app did the rest.

How It WorksNov 18, 2024

Infostealers, and Why a Password You Changed Years Ago Can Still Burn You

Infostealer malware quietly harvests credentials and sessions from endpoints, and they circulate for years. Here is how the pipeline works and why enforced MFA is the control that defuses it.

Anatomy of an Identity IncidentJul 15, 2024

It Wasn't a Vulnerability. It Was a Setting Left Off.

Anatomy of an Identity Incident — Snowflake, 2024. The platform was never breached. Around 165 customers were, because multi-factor authentication was optional and nobody made it mandatory.

How It WorksMay 21, 2024

Token Signing, and What "Token Forgery" Actually Means

Modern auth tokens are trusted because they're signed. Here is how signing works, what a signing key really is, and why stealing one means an attacker can mint valid identities at will.

Anatomy of an Identity IncidentFeb 5, 2024

The Test Account That Read the Executives' Email

Anatomy of an Identity Incident — Midnight Blizzard, January 2024. A forgotten test account with no MFA, and a forgotten app with too much access, were enough to reach senior leadership's inbox.

Anatomy of an Identity IncidentNov 30, 2023

When the Vendor Is Breached but the Incident Is Yours

Anatomy of an Identity Incident #1 — Okta's support case system, October 2023. What broke at the identity layer, and who was actually responsible for catching it.

How It WorksOct 30, 2023

OAuth Tokens Explained: Why Changing Your Password Doesn't Kick the Attacker Out

OAuth is how you let one app access another without sharing a password. Here is what the tokens are, why they outlive your password, and why a connected app is its own standing identity.

Anatomy of an Identity IncidentOct 10, 2023

A Phone Call Beat Every Control

Anatomy of an Identity Incident — MGM and Caesars, September 2023. No exploit, no malware. Someone called the help desk, and the help desk issued an identity to the wrong person.

Anatomy of an Identity IncidentSep 12, 2023

Nothing Was Stolen. The Tokens Were Forged.

Anatomy of an Identity Incident — Storm-0558, 2023. A leaked signing key let an attacker mint valid identities for anyone. No password was guessed, because none was needed.

How It WorksJun 12, 2023

What Really Happens When the Help Desk Resets Your MFA

Account recovery is the one flow designed to grant access to someone who can't prove who they are. Here is what the reset actually does, and why it's the weakest point in your identity stack.

Anatomy of an Identity IncidentMar 5, 2023

The Vault Was Only as Safe as a Home Computer

Anatomy of an Identity Incident — LastPass, 2022. The decryption keys to every customer's vault backups were reachable through one engineer's personal home PC.

How It WorksFeb 27, 2023

SCIM Provisioning: How It Works and the Places It Silently Breaks

SCIM is how accounts get created and removed across your apps automatically. Here is the mechanism, and the failure modes that leave access lingering.

Anatomy of an Identity IncidentFeb 20, 2023

2FA Was On. The Session Walked Out Anyway.

Anatomy of an Identity Incident — CircleCI, January 2023. Malware lifted a 2FA-backed session off one laptop, and a CI platform's vault of customer secrets emptied out.

How It WorksNov 9, 2022

The Lifecycle of a Service Account Nobody Owns

Service accounts are created in a hurry and outlive everyone who remembers them. Here is the full lifecycle, and where it quietly goes wrong.

Anatomy of an Identity IncidentOct 5, 2022

The Push Notification Was Never the Real Problem

Anatomy of an Identity Incident — Uber, September 2022. Everyone remembers the MFA fatigue. The breach that mattered happened one layer deeper, in a script no one owned.

Anatomy of an Identity IncidentSep 12, 2022

Same Phish, Two Outcomes

Anatomy of an Identity Incident — the 0ktapus campaign, 2022. One phishing kit hit 130-plus companies. Why most got breached and at least one didn't comes down to a single control.

How It WorksAug 14, 2022

One-Time Codes vs. Passkeys: What "Phishing-Resistant" Actually Means

Not all multi-factor authentication is equal. Here is the mechanical reason a security key or passkey stops phishing that a six-digit code can't.

How It WorksMay 22, 2022

What's Inside a HAR File — and Why You Should Scrub It Before You Share It

Support asks for a HAR file and you upload one without thinking. Here is what's actually in it, why it can contain live credentials, and how to strip them first.

Anatomy of an Identity IncidentApr 5, 2022

Your Vendor's Subcontractor Is Your Attack Surface

Anatomy of an Identity Incident — Okta and Sitel, January 2022. The breach happened on a support subcontractor's laptop. The blast radius was every customer tenant that laptop could reach.

How It WorksMar 2, 2022

How Session Tokens Actually Work (and Why MFA Can't Save a Stolen One)

A plain walkthrough of what a session token is, why it exists, and the reason multi-factor authentication does nothing once one has been stolen.

Series