Detecting Account Compromise Is Harder Than Ever. Vectra AI Catches What Native Signals Miss

September 2, 2026
9/2/2026
Jesse Lord
Staff Data Scientist
Detecting Account Compromise Is Harder Than Ever. Vectra AI Catches What Native Signals Miss

Detecting initial access is a signal fidelity problem. Most identity tooling gets it wrong in both directions, drowning analysts in noise while missing real compromises. Vectra AI research into confirmed account compromises shows the difference signal fidelity can make: sophisticated compromises surfaced by Vectra AI were buried among roughly 200 native risk alerts an analyst would otherwise need to triage.  This post covers why native signals fall short and how Vectra AI’s models detect what they miss.

Nearly every serious intrusion has a sign-in at the front of it. An attacker holding valid credentials isn't exploiting anything. They're authenticating, and authentication is working as designed. Catch that moment and the incident is a password reset. Miss it and you spend the next month chasing persistence, mailbox rules, and exfiltration.

So why do so few SOC teams trust their initial-access alerts?

Anomaly detection fires on change. New country, new IP or new device. But change is constant in a real organization. Analysts learn to close those alerts on sight. Meanwhile, the compromises that matter often aren't anomalous by those measures: ten minutes on LinkedIn lets an attacker arrive from the right country on the right operating system. A SOC relying solely on native risk signals inherits that ceiling as its security posture. They are bounded by signals attackers have already learned to stay under.

Not every signal costs the same to fake. And native signals are built on the cheap ones

The useful question about a sign-in attribute isn't whether it's unusual. It's what reproducing it would cost an attacker.

Tier Signal Cost
Cheap to imitate Operating system, browser, approximate geography Public information plus a commodity proxy covers all three in minutes, for a few dollars.
Costly to acquire A device already registered and trusted in the organization’s identity provider (IdP) Attackers generally can’t obtain one. They can register a new device, but registration is itself a conspicuous, observable event.
Hard to even know Network history and application behavior Has this identity authenticated from this network before? Has anyone else in the organization?

That last category is arguably the hardest to model and the most important, because it's the one attackers can't buy their way out of.

This is the fallacy of relying on native signal alone. Native risk signals are largely built from the first row such as IP reputation, geography and client attributes. Attackers control these. Worse, they behave largely the same across tenants so attackers get to rehearse against them. A technique that stays under the risk threshold in one environment likely stays under it everywhere.

The signals in the last row invert that. Network and application history exist only inside your organization, so there is nothing external to practice against and nothing to look up.

The Vectra AI Approach: Multi-dimensional baselines, weighted by cost

At Vectra AI, our initial access detections are built on AI models that learn multi-dimensional baselines: statistical representations of how sign-in activity normally looks for each human and non-human identity and for the organization around it. This includes network history, geography, device and client attributes, and application behavior. The models learn distributions continuously from the organization's own activity. No single dimension decides on its own. A sign-in is read the way an experienced analyst would read it: as one moment held against everything already known about the identity and the organization it is part of.

Because the baselines are learned probability distributions, every new sign-in can be scored by its surprisal - a measure from information theory that grades exactly how improbable each observation is given everything the model has learned. Routine activity scores low. Genuinely unprecedented activity scores high. The enormous middle ground is where most real work happens.

Then the cost-to-fake ordering does the weighting. High surprisal on something trivially spoofable earns little; on something an attacker couldn't have known earns more. The detection doesn't fire on novelty. It fires on novelty that would have been expensive to manufacture.

The impact, measured against confirmed attacks: high fidelity detection and prioritization. For context, Microsoft's native risk signals rated those same sign-ins no higher than medium, a tier where an analyst must triage roughly 200 alerts for every real compromise the Vectra AI model surfaces as one.

Proofpoint: AI that learns history vs alerts that panic at every change

Consider the alert almost every SOC has closed a hundred times. An employee who normally works from the U.S. flies to the company's Sydney office.

Native alerts panic: new country, new IP, new network. An analyst spends twenty minutes confirming a business trip. Multiply by every traveler, every week. This is the archetypal alert-fatigue SecOps deals with.

An attacker, meanwhile, bypasses those same alerts for a few dollars: a VPN endpoint in the right country, the right OS, an apt user agent. Cheap-to-imitate attributes mean native signals see nothing worth flagging.

The Vectra AI surprisal model reads both moments correctly, because it's scoring against history the attacker can't see. The traveler's "new" network isn't new to the organization. Hundreds of colleagues already authenticate through the provider serving that office. The attacker's sign-in fails that same test. A network no one in the tenant has used, an unregistered device, and a beeline for the broad-access entry points every fresh credential thief needs. Cheap attributes score low, expensive ones score high. The result is one coherent attack narrative.

Initial Access: An evolving problem and how defenders stay ahead Initial access detection is not a static problem.

The techniques that bypass native signals are increasingly democratized: proxy infrastructure, residential IP services, and session-hijacking toolkits that once required real capability are now commodity purchases. The baseline attacker keeps getting better without getting smarter.

There are also genuine boundary cases. An employee on airport Wi-Fi, on an unmanaged device, over a network no one in the tenant has touched, can brush against the same pattern early-stage intrusion produces. It occasionally earns an alert worth explaining.

This is why Vectra AI models are built as a dynamic learning system rather than a static rule set. Models are continuously evaluated against production outcomes and confirmed attacks, boundary cases feed back into refinement, and as new access techniques emerge, the baselines and weightings move with them. Attackers iterate on what's cheap to change. The models learn from what attackers can't hide and that loop is how the detection stays ahead.

Takeaway

Initial access is where detection pays off meaningfully and where most tooling earns the least trust. Detection engines that weigh every signal equally give attackers room to maneuver. Weighting signals by what they cost to reproduce, against baselines learned from an organization's own history, inverts that. Routine change stops firing, and the alerts that do fire are worth investigating. That inversion is what Vectra AI's initial access models are built on.

The result: analysts act instead of triage. Leaders see compromise at the password-reset stage, not the IR stage.

The same signal problem extends well beyond initial access. Once an attacker gets in, they move across identities, networks, cloud services, SaaS applications, endpoints, OT and IoT environments, and increasingly AI agents, leaving pieces of the attack story across the modern attack surface. The Vectra AI Platform brings those signals together, applies AI to understand attacker behavior and context, and correlates activity as the attack progresses. The result is high-fidelity Attack Signal Intelligence that follows the attack wherever it moves, so security teams can see what matters earlier, understand what the attacker is doing, and act with confidence.

Explore the Vectra AI Platform →

FAQs