2026 Critical Enterprise Intrusion Chain Detection: Privileged Role Assignment Shortly After Suspicious Sign-In
Detects when a user account assigned to a highly privileged directory or cloud role performs the assignment shortly after exhibiting signs of compromise, such as risky sign-ins, anomalous locations, or suspected session token reuse.
CQL

