Terminology Index
Glossary
2953 terms
A32
Authentication Alerts
SOC alerts triggered by login and identity events, such as failed-login bursts, impossible travel, or logins from unusual locations or devices. They are a frequent and high-value alert category because attackers often start by abusing credentials.
Because so many attacks begin with stolen or guessed credentials, authentication alerts are central to a SOC's daily work. Triaging them means gathering context, the user, location, device, and prior behavior, to decide whether the activity is benign or a sign of account compromise.
Introduced in: SOC Analyst Fundamentals
Examples
- An impossible-travel alert when a user logs in from two distant places minutes apart.
- A burst of failed logins suggesting password guessing.
- A successful login from a country the user has never used before.
