Book a demo call with us
Cross icon
Qevlar AI
Logo Qevlar

Identity threat hunting, built into every investigation

Meet Qevlar Identity Hunt, the identity analysis engine running autonomously every time a user is involved in an investigation

Natalia Kazankova
Natalia Kazankova
Principal Product Marketing Manager
Identity threat hunting, built into every investigation

TL;DR

  • Credential attacks appear in 39% of all breaches, but most SOC teams don't have the capacity to analyze identity properly on every alert.
  • Qevlar AI does it automatically, building a per-user behavioral baseline and returning an actionable verdict in under 10 seconds on every investigation where a user appears, even when the original alert has nothing to do with identity.

Credential attacks are among the most reliable ways into enterprise environments right now. The 2026 Verizon Data Breach Investigations Report found credential abuse present at some point in 39% of all breaches, the highest of any action type, and the report is explicit: "credentials are an integral part of the threat actor's toolkit."

Password spraying, MFA fatigue, credential stuffing, account takeover. They land in authentication logs that most SOC teams have neither the time nor the tooling to work through properly.

The problem is that a medium-sized enterprise generates thousands of authentication events every day, and almost all of them are completely routine. To find an anomaly, you need to know what's normal for that specific user, and most tooling doesn't.

SOC teams have had essentially two options, and neither has worked

The first is rule-based detection

  • Flag logins from unusual countries.
  • Alert on impossible travel.
  • Anomalous amount of authentication attempts.

This makes sense until you realize "unusual" isn't a fixed thing. A login from China is unremarkable for one user and a serious signal for another. Rules that cover everyone end up covering no one well. The result is a steady stream of alerts analysts learn to dismiss, and real attack patterns sitting quietly inside the noise.

UEBA was supposed to be the answer

Build a baseline per user and flag what deviates from it.

The problem is these tools were built before AI could do the follow-through. They tell analysts something is abnormal. They don't say whether it matters. Figuring that out requires pulling authentication logs, mapping IP infrastructure, checking device data, cross-referencing threat intelligence, and actually making a call.

For an analyst on 20 alerts a day, most alerts don't get that treatment. So UEBA flags pile up, verdicts almost never come, and analysts learn to treat identity alerts as background noise. Technically, the tool is running. In practice, nobody's acting on it.

Meet Qevlar Identity Hunt

The question SOC teams have always faced with identity is not whether to investigate it. It's whether there is capacity to do it properly, on every alert, every time. There usually isn't.

That’s why we added Identity Hunting into Qevlar. Qevlar runs the identity analysis on every investigation automatically, returning a verdict with reasoning before the analyst has finished reading the alert. Even when everything looks legitimate, Qevlar checks the human behind it to ensure it’s not an attacker pretending to look like a normal user.

How it works

Every time an investigation involves a user observable, Qevlar automatically builds that user's authentication baseline from ~30 days of sign-in logs and hunts for activity that deviates from it, even when the alert that triggered the investigation has nothing to do with identity.

It works in three layers.

First, a per-user behavioral model built from sign-in history: normal countries, devices, IP ranges, access patterns. A profile specific to that individual, because a login from Germany is routine for one user and anomalous for another, and a rule that treats both the same way is useless for both.

Second, rule-based detection that fires on patterns universally suspicious regardless of who the user is: brute force sequences, impossible travel, MFA fatigue chains.

Third, an LLM with live CTI access that takes the statistical signals and rule flags, weighs the evidence, and returns a verdict with human-readable reasoning.

Every identity analysis returns:

  • Verdict: Malicious, Not Harmful, or Inconclusive, with reasoning
  • Attack pattern: credential stuffing, password spray, brute force, MFA fatigue, account takeover, credential exposure
  • Reach and impact: blocked, partial access, or full compromise
  • Infrastructure attribution: specific VPN services, hosting providers (DigitalOcean, M247, OVH), anonymization tools (Tor, Apple Private Relay, ProxyEmpire)
  • Compliance signals: consumer VPN usage, proxy services, privacy relay detection
  • Attack scale: malicious IP count, geographic distribution of attack infrastructure.

It takes under 10 seconds. And it runs on 100% of investigations where a user appears.

Real investigation example

Last week, a Microsoft Defender alert fired at a European enterprise: "Defense evasion and Collection" on one user account. Inbox rules created with concealment parameters. Analysts see this pattern constantly. It usually turns out to be nothing.

Surface signals pointed to benign:

  • The session used valid tokens.
  • Entra flagged no sign-in risk.
  • The source IP had no abuse history in CTI.
  • Device telemetry was clean.
  • On Microsoft's signals alone, this investigation closes as routine user activity.

Qevlar checked the user's authentication baseline:

  • The session came from a UK hosting IP that had never appeared in this user's sign-in history.
  • Normal activity for this user was from Italy, on a managed corporate device.
  • While the attacker's session was running from a UK datacenter, the user's legitimate activity from Italy was continuing concurrently. Two separate sessions, active at the same time.

The attacker created an inbox rule to hide incoming mail from specific external domains: archive it, mark it as read, stop further processing.

Verdict:

  • Malicious, high severity.
  • Account takeover with partial access.
  • The customer confirmed the finding.

The pivot into authentication history is exactly what this investigation needed, and exactly what the surface signals told the analyst not to bother with: valid tokens, no sign-in risk, clean IP reputation, clean device. Every gate a human uses to decide whether a pivot is worth the time said no. Qevlar doesn't use those gates — it pulls the baseline on every investigation, in seconds, whether or not the alert looks like it's about identity.

The alert told analysts what happened. Qevlar revealed what it meant. Without Identity Hunt, this investigation closes clean, the account stays compromised, and the inbox rule keeps running.

Identity Hunt is available now for all Qevlar customers, enabled by default with no configuration required. Book a demo to see it live on a real investigation.

Published on
August 13, 2026
Updated on
August 13, 2026
Table of content
H2 toc

Frequently asked questions

"My Identity Provider already does this."

bar
bar

An Identity Access Management system flags identity events in isolation and adds them to the alert queue. Qevlar brings identity context inside every investigation across every alert type: endpoint, email, cloud, network. The signal arrives where the decision is being made, not as alert number 401 in a separate console.

"My analysts already check user behavior."

bar
bar

In theory. In practice, nobody pivots into 30 days of authentication logs for an endpoint alert where all the surface signals look clean. There's no trigger and no time. Qevlar does it on 100% of investigations, in seconds.

See how much of your manual workload can be automated