Identity is the new perimeter — and the new forensic timeline
When an attacker signs in with legitimate credentials, endpoint artefacts arrive late and incomplete. The earliest reliable evidence lives in identity logs: token issuance, device registration, conditional-access decisions and consent grants for third-party applications.
Our forensics students learn to build a timeline from those events first, then corroborate with host and network data. That ordering matters. Starting on the endpoint routinely costs investigators days and leaves persistence — an added authenticator, a lingering OAuth grant — untouched after remediation.
The practical checklist we teach: preserve identity logs before they roll off retention, enumerate every non-human credential in the blast radius, and treat consent grants as first-class persistence mechanisms rather than an application concern.
REY Research Lab
This note comes from the REY Cyber Forensics & Cybersecurity Research Lab, where our training programs and casework are developed.