{"id":3371,"date":"2026-09-09T15:08:27","date_gmt":"2026-09-09T20:08:27","guid":{"rendered":"https:\/\/minnovatenetworks.com\/blog\/stolen-session-not-stolen-password\/"},"modified":"2026-09-09T15:43:29","modified_gmt":"2026-09-09T20:43:29","slug":"stolen-session-not-stolen-password","status":"publish","type":"post","link":"https:\/\/minnovatenetworks.com\/blog\/stolen-session-not-stolen-password\/","title":{"rendered":"They did not break in. They signed in."},"content":{"rendered":"<p>There is a moment in most breach timelines where the language quietly changes. Up to that point the attacker is doing attacker things: probing, phishing, running tools. After it, they are just a user. They log in during business hours, open a mailbox, read some files, and every system involved considers this entirely normal, because it is.<\/p>\n<p>That moment is when they get a working identity. It is the most important transition in the whole event and it is the one most environments are least equipped to notice.<\/p>\n<h2>Why the endpoint sees nothing<\/h2>\n<p>Endpoint detection watches machines. It is very good at that. But an attacker who has your credentials and a session token does not need to touch a machine in your practice at all. They sign into Microsoft 365 from their own hardware, somewhere else, and read your mail through a browser.<\/p>\n<p>There is no process to flag, no file to inspect, no malware to detect. The endpoint agent is working perfectly and has nothing to report, because nothing happened on the endpoint.<\/p>\n<h2>Multi-factor helps, and it is not a wall<\/h2>\n<p>Multi-factor authentication remains the single highest-value control you can turn on, and if it is not on every account in your practice, stop reading and go and fix that first.<\/p>\n<p>It is worth understanding what it does and does not stop. There are three routine ways around it, none of which are exotic:<\/p>\n<ul>\n<li><strong>Prompt fatigue.<\/strong> The attacker has the password and simply triggers approval requests repeatedly, often at three in the morning. Eventually somebody taps approve to make the phone stop.<\/li>\n<li><strong>Real-time relay.<\/strong> A convincing fake login page passes your credentials and your code straight through to the real service as you type them. You are actually signing in. The attacker is standing in the middle collecting the resulting session.<\/li>\n<li><strong>Token theft.<\/strong> The session token issued after a successful login is what keeps you signed in. Steal that and multi-factor is not asked for again, because as far as the service is concerned it already happened.<\/li>\n<\/ul>\n<p>Number-matching prompts help against the first. Phishing-resistant methods help against the second. Nothing at the login stage helps against the third, because the theft happens after the login succeeded.<\/p>\n<h2>What identity threat detection actually watches<\/h2>\n<p>This is why we run identity threat detection and response as a separate control from endpoint security. It watches the accounts rather than the machines, looking for what a compromised identity does that a real user does not:<\/p>\n<ul>\n<li><strong>Impossible travel.<\/strong> A sign-in from your office and another from a different continent forty minutes later.<\/li>\n<li><strong>New mailbox rules.<\/strong> Attackers create forwarding or auto-delete rules almost immediately, to keep a copy of the mail and to hide replies from the real owner. A rule that quietly moves anything containing the word &#8220;invoice&#8221; into a folder nobody opens is a red flag with no innocent explanation.<\/li>\n<li><strong>A new multi-factor method registered.<\/strong> If an attacker adds their own authenticator to your account, they no longer need to defeat it again. This is a very common persistence step and it is close to invisible unless something is specifically watching for it.<\/li>\n<li><strong>Unusual mailbox delegation.<\/strong> Someone granting themselves access to another person&#8217;s mailbox.<\/li>\n<li><strong>Privilege escalation.<\/strong> An ordinary account suddenly acquiring administrative rights.<\/li>\n<\/ul>\n<h2>Detection is only half of it<\/h2>\n<p>Knowing an account is compromised is useful for as long as it takes to do something, and the something has an order that matters.<\/p>\n<p>Resetting the password is the obvious first move and on its own it is not enough. Existing sessions stay valid, which means the attacker stays signed in while you congratulate yourself. Sessions have to be revoked explicitly. Then the multi-factor methods have to be reviewed, because if they registered their own, a password reset simply hands them a fresh login. Then the mailbox rules, then the delegation, then an honest look at what was accessed while they were inside.<\/p>\n<p>That sequence takes a while to work through under pressure at four in the afternoon, which is exactly why it should be a runbook rather than an improvisation.<\/p>\n<h2>The short version<\/h2>\n<p>Endpoint security answers &#8220;is something bad running on this machine?&#8221; Identity security answers &#8220;is this actually the person it claims to be?&#8221; They are different questions, they need different tooling, and in most environments the second one currently has nobody assigned to it.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Once an attacker has a valid login, nothing on the endpoint objects and nothing in the firewall log looks wrong. Watching the identity itself is a separate job from watching the machine.<\/p>\n","protected":false},"author":0,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[56],"tags":[74,72,71,63,73],"class_list":["post-3371","post","type-post","status-publish","format-standard","hentry","category-identity-security","tag-account-takeover","tag-identity","tag-itdr","tag-microsoft-365","tag-multi-factor-authentication"],"_links":{"self":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3371","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=3371"}],"version-history":[{"count":1,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3371\/revisions"}],"predecessor-version":[{"id":3376,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/posts\/3371\/revisions\/3376"}],"wp:attachment":[{"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=3371"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=3371"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/minnovatenetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=3371"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}