Meet Qevlar Identity Hunt, the identity analysis engine running autonomously every time a user is involved in an investigation

Credential attacks are among the most reliable ways into enterprise environments right now. The 2026 Verizon Data Breach Investigations Report found credential abuse present at some point in 39% of all breaches, the highest of any action type, and the report is explicit: "credentials are an integral part of the threat actor's toolkit."
Password spraying, MFA fatigue, credential stuffing, account takeover. They land in authentication logs that most SOC teams have neither the time nor the tooling to work through properly.
The problem is that a medium-sized enterprise generates thousands of authentication events every day, and almost all of them are completely routine. To find an anomaly, you need to know what's normal for that specific user, and most tooling doesn't.
This makes sense until you realize "unusual" isn't a fixed thing. A login from China is unremarkable for one user and a serious signal for another. Rules that cover everyone end up covering no one well. The result is a steady stream of alerts analysts learn to dismiss, and real attack patterns sitting quietly inside the noise.
Build a baseline per user and flag what deviates from it.
The problem is these tools were built before AI could do the follow-through. They tell analysts something is abnormal. They don't say whether it matters. Figuring that out requires pulling authentication logs, mapping IP infrastructure, checking device data, cross-referencing threat intelligence, and actually making a call.
For an analyst on 20 alerts a day, most alerts don't get that treatment. So UEBA flags pile up, verdicts almost never come, and analysts learn to treat identity alerts as background noise. Technically, the tool is running. In practice, nobody's acting on it.
The question SOC teams have always faced with identity is not whether to investigate it. It's whether there is capacity to do it properly, on every alert, every time. There usually isn't.
That’s why we added Identity Hunting into Qevlar. Qevlar runs the identity analysis on every investigation automatically, returning a verdict with reasoning before the analyst has finished reading the alert. Even when everything looks legitimate, Qevlar checks the human behind it to ensure it’s not an attacker pretending to look like a normal user.
Every time an investigation involves a user observable, Qevlar automatically builds that user's authentication baseline from ~30 days of sign-in logs and hunts for activity that deviates from it, even when the alert that triggered the investigation has nothing to do with identity.

It works in three layers.
First, a per-user behavioral model built from sign-in history: normal countries, devices, IP ranges, access patterns. A profile specific to that individual, because a login from Germany is routine for one user and anomalous for another, and a rule that treats both the same way is useless for both.
Second, rule-based detection that fires on patterns universally suspicious regardless of who the user is: brute force sequences, impossible travel, MFA fatigue chains.
Third, an LLM with live CTI access that takes the statistical signals and rule flags, weighs the evidence, and returns a verdict with human-readable reasoning.

Every identity analysis returns:

It takes under 10 seconds. And it runs on 100% of investigations where a user appears.
Last week, a Microsoft Defender alert fired at a European enterprise: "Defense evasion and Collection" on one user account. Inbox rules created with concealment parameters. Analysts see this pattern constantly. It usually turns out to be nothing.
Surface signals pointed to benign:
Qevlar checked the user's authentication baseline:
.png)
The attacker created an inbox rule to hide incoming mail from specific external domains: archive it, mark it as read, stop further processing.
Verdict:
The pivot into authentication history is exactly what this investigation needed, and exactly what the surface signals told the analyst not to bother with: valid tokens, no sign-in risk, clean IP reputation, clean device. Every gate a human uses to decide whether a pivot is worth the time said no. Qevlar doesn't use those gates — it pulls the baseline on every investigation, in seconds, whether or not the alert looks like it's about identity.
The alert told analysts what happened. Qevlar revealed what it meant. Without Identity Hunt, this investigation closes clean, the account stays compromised, and the inbox rule keeps running.
Identity Hunt is available now for all Qevlar customers, enabled by default with no configuration required. Book a demo to see it live on a real investigation.
An Identity Access Management system flags identity events in isolation and adds them to the alert queue. Qevlar brings identity context inside every investigation across every alert type: endpoint, email, cloud, network. The signal arrives where the decision is being made, not as alert number 401 in a separate console.
In theory. In practice, nobody pivots into 30 days of authentication logs for an endpoint alert where all the surface signals look clean. There's no trigger and no time. Qevlar does it on 100% of investigations, in seconds.