2026 Critical Enterprise Intrusion Chain Detection: Privileged Role Assignment Shortly After Suspicious Sign-In

Detects when a user account assigned to a highly privileged directory or cloud role performs the assignment shortly after exhibiting signs of compromise, such as risky sign-ins, anomalous locations, or suspected session token reuse.