Identity is now a critical starting point for investigating a cyber incident. On August 7, 2026, Unit 42 said weaknesses in identity played a role in nearly 90% of the incidents it investigated. Its 2026 report also attributes 65% of initial-access activity to identity-based techniques.

Those figures do not mean every incident begins with a stolen password, or that identity controls explain the entire attack. They do point to a practical change in triage: an unusual login, authentication prompt or help-desk interaction needs to be examined alongside what happened next.

Start by identifying the access route

Unit 42 lists credential theft, manipulation of multifactor authentication, session hijacking and social engineering among identity-based initial-access techniques. Its recent investigations also include phishing, social-engineering calls, MFA fatigue attacks, compromised third-party accounts and abuse of help-desk procedures.

These routes look different in an investigation, but they lead to the same first question: which identity or support process gave the attacker a foothold?

Group the available signals around that question. Review a suspicious login with authentication prompts, help-desk activity, third-party access and reports of phishing or social-engineering contact. The purpose is not to treat every unusual event as a breach. It is to avoid judging each signal in isolation when several events may describe one intrusion.

The access route may already be clear, or it may remain uncertain. Record that distinction at the start. A suspicious identity event is not, by itself, proof that persistence, privilege escalation or lateral movement followed.

Trace the progression after access

Unit 42 describes a post-access progression that can include establishing persistence, raising privileges and moving laterally through multiple environments. That sequence gives the investigation a useful order.

  1. Identify the first credible access event. Record whether the suspected route involved credentials, MFA manipulation, a hijacked session, a third-party account or a help-desk process.
  2. Check the identity changes that followed. Look for signs that access expanded or became harder to remove, particularly when the investigation already indicates persistence or privilege escalation.
  3. Map every environment touched. Unit 42 reports that 87% of incidents in its 2026 report extend across multiple attack surfaces. A review confined to one environment can therefore miss part of the progression described in the report.
  4. Connect the activity to the likely objective. Unit 42 associates identity compromises with ransomware deployment, data theft, financial fraud and long-term persistence. The suspected objective helps determine which downstream activity needs the fastest attention.
  5. Revisit signals initially treated as low priority. Unit 42 says malicious activity may already be present in an organisation’s security controls but appear unimportant when isolated without automated correlation.

This order keeps evidence and interpretation separate. The access route may be confirmed while the attacker’s objective remains uncertain. Likewise, later privilege changes may be visible without proving that every suspected movement event belongs to the same intrusion. Keep each conclusion tied to the evidence that supports it.

Build one timeline across the affected surfaces

Unit 42 analysts use the Cortex SecOps platform to bring security telemetry into a single investigation view. The broader lesson is about visibility: identity, authentication and other security signals need to be examined together when an incident crosses surfaces.

Teams reviewing an incident manually can apply the same principle with the controls already in place. Create one timeline for the suspected account, session or support interaction. Attach the related events from each affected environment and place the initial-access event beside the later identity changes, privilege activity and movement.

If the timeline cannot show how the access event connects to later activity, the investigation is incomplete rather than settled. That does not prove a compromise occurred, but it does show that the available signals do not yet support closure.

Automation can improve correlation, but it does not remove the need for judgement. A linked sequence is more useful than a large collection of unrelated alerts. Even then, the evidence may support several explanations, so do not declare a complete attack path until the stages are connected.

Include the human and third-party channels

Muddled Libra, also known as Scattered Spider, is cited by Unit 42 as an example of a group using social engineering and identity abuse. An identity investigation therefore cannot be limited to technical authentication records.

Calls, phishing messages, MFA prompts, third-party accounts and help-desk interactions can all form part of the route into an environment. When one of these channels appears in the evidence, review it alongside the account activity instead of treating it as a separate incident.

This matters most when the original access event looks ordinary on its own. The compromise may depend on the interaction between a person, a support procedure and an identity control. That interaction can explain why a single login or reset request did not initially appear significant.

Escalate when the signals form a sequence

Escalate the investigation when the evidence shows a connected progression: an initial-access route followed by persistence, privilege escalation or movement between environments. Escalation is also warranted when activity touches several attack surfaces or aligns with an objective Unit 42 associates with identity compromise, including ransomware deployment, data theft, financial fraud or long-term persistence.

Unit 42 says its Managed Detection and Response team investigates suspicious activity continuously, while its threat hunters proactively search for identity-compromise indicators that have not yet triggered an alert. Organisations without that level of continuous coverage should treat the absence of an alert as an absence of confirmation, not as proof that no compromise exists.

The distinction affects the next action. A confirmed chain should be handled as a connected incident. An unexplained gap should lead to more correlation and review of the relevant environments, while an isolated anomaly should remain labelled as suspicious until additional evidence changes its status.

What changes in day-to-day triage

Unit 42’s findings support a clear working rule: investigate the identity event, connect it to surrounding telemetry and verify what changed across environments before closing the case.

The figures do not establish that every organisation faces the same route, and they do not show that identity controls can replace broader security monitoring. The practical compromise is that teams must correlate more evidence while preserving uncertainty where the evidence is incomplete.

For security teams, the useful result is a more disciplined order of work. Start with the access route, follow the identity and environment changes, test the likely objective, then return to alerts that looked unimportant alone. That sequence makes it easier to prioritise the signals that explain how an intrusion began and where it went next.

Official sources

Sources and methodology

  1. Official source: unit42.paloaltonetworks.com Opens an external source
  2. Official source: unit42.paloaltonetworks.com Opens an external source