CYBER DELTA FORCESearch

Inside the Modern SOC: The Identity Front Door

Identity-based attacks drive 90% of incidents.

CDF News DeskPalo Alto Unit 428 Aug 2026, 4:30 am
Image courtesy of Palo Alto Unit 42. Original report
CDF REPORT

Identity-based attacks drive 90% of incidents. Learn how modern attackers exploit identities and what SOC leaders can do to respond. According to the 2026 Unit 42 Global Incident Response Report , identity weaknesses played a role in nearly 90% of incidents investigated by Unit 42. The report also found that 65% of initial access activity involved identity-based techniques, underscoring how credential theft, multifactor authentication (MFA) manipulation, session hijacking and social engineering have become some of the most effective ways to gain access to enterprise environments.

In our next entry in this series, we'll examine why modern attacks increasingly cross security domains and why unified visibility has become essential for detecting and stopping multi-surface attacks before they escalate into business impact. Identity attacks have become one of the most effective ways for adversaries to bypass traditional security controls.

Expansion through identity: Once inside, attackers exploit identity weaknesses to establish persistence, compromise additional accounts and escalate privileges to strengthen their foothold. Organizations using Managed XSIAM extend this approach through AI-driven correlation, integrated investigation and response workflows and continuous SOC engineering delivered by Unit 42 experts. Rather than requiring internal teams to continuously engineer and optimize the platform as attacker techniques evolve, our experts refine: This helps organizations identify identity-driven attacks earlier and accelerate response before attackers can expand their access. Correlating identity activity with endpoint, cloud, SaaS and network telemetry provides the behavioral context needed to distinguish legitimate users from compromised accounts.

A social-first entry: Threat groups such as Muddled Libra (aka Scattered Spider) demonstrate how many attackers increasingly rely on social engineering and identity abuse as part of their toolkit. An initial compromised identity can quickly become a multi-domain investigation that requires defenders to connect activity across the environment. The objective: Whether the objective is ransomware deployment, data theft, financial fraud or long-term persistence, identity compromise often serves as the foundation for broader attacker objectives. When investigating identity-driven attacks, our Unit 42 analysts use the Cortex SecOps platform to unify security telemetry into a single investigative view, allowing them to quickly validate suspicious activity and understand the full scope of the attack.

What changed

Our 24/7 Managed Detection and Response (MDR) team continuously investigates suspicious activity while our threat hunters proactively search for signs of identity compromise that may not yet have generated an alert.

Unit 42 combines expert-led Managed Detection and Response (MDR), proactive threat hunting, continuous SOC engineering and frontline incident response expertise to help organizations identify identity-driven attacks earlier and respond with greater confidence.

Who is affected

Expansion through identity: Once inside, attackers exploit identity weaknesses to establish persistence, compromise additional accounts and escalate privileges to strengthen their foothold.

Organizations using Managed XSIAM extend this approach through AI-driven correlation, integrated investigation and response workflows and continuous SOC engineering delivered by Unit 42 experts.

Rather than requiring internal teams to continuously engineer and optimize the platform as attacker techniques evolve, our experts refine: This helps organizations identify identity-driven attacks earlier and accelerate response before attackers can expand their access.

Correlating identity activity with endpoint, cloud, SaaS and network telemetry provides the behavioral context needed to distinguish legitimate users from compromised accounts.

Why this matters

In our next entry in this series, we'll examine why modern attacks increasingly cross security domains and why unified visibility has become essential for detecting and stopping multi-surface attacks before they escalate into business impact.

Identity attacks have become one of the most effective ways for adversaries to bypass traditional security controls.

How organizations are responding

A social-first entry: Threat groups such as Muddled Libra (aka Scattered Spider) demonstrate how many attackers increasingly rely on social engineering and identity abuse as part of their toolkit.

An initial compromised identity can quickly become a multi-domain investigation that requires defenders to connect activity across the environment.

The objective: Whether the objective is ransomware deployment, data theft, financial fraud or long-term persistence, identity compromise often serves as the foundation for broader attacker objectives.

When investigating identity-driven attacks, our Unit 42 analysts use the Cortex SecOps platform to unify security telemetry into a single investigative view, allowing them to quickly validate suspicious activity and understand the full scope of the attack.

AI-driven correlation, behavioral context and Unit 42 threat intelligence help our teams quickly validate high-confidence incidents and determine the full scope of attacker activity.

As identity attacks continue to evolve, security leaders should focus on the operational challenges that often prevent teams from detecting identity-driven attacks early.

What to watch next

Watch for additional exploitation reporting, newly published indicators, and changes to vendor guidance.

What remains unknown

The available reporting does not establish whether the issue is being actively exploited in the wild.

MORE IN CLOUD & IDENTITY

More cybersecurity reporting

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev ServersThe Hacker News · 15 Sept 2026, 4:42 pmChina-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEThe Hacker News · 15 Sept 2026, 11:01 amTwitch extension with 30K installs exposes users’ OAuth tokensBleepingComputer · 15 Sept 2026, 12:33 amUnmasking Cloud Identities: From Behavioral Clustering to Automated DetectionPalo Alto Unit 42 · 14 Sept 2026, 3:30 pm