Agents read sign-ins and mailbox activity per account, and raise one explained finding when behavior stops matching the owner.












A phishing proxy keeps the session cookie, so no second factor is asked for. Every step after the login looks legitimate.
of MFA-bypass attacks used token theft, the most common technique.
Verizon 2025 Data Breach Investigations ReportFour ways past MFA
Each signal is weak alone. Together, inside 24 minutes, on an account that has never made a rule, they fit a stolen session preparing fraud.
Sign-in, Chicago, known laptop. MFA satisfied.203.0.113.24 · Windows / Edge
NormalSign-in, Amsterdam, first-seen device, hosting provider.198.51.100.77 · Linux / Chrome
6,600 km in 19 minNew inbox rule named “.”: mail containing invoice, payment or wire moved to RSS Subscriptions and marked read.
Hidden ruleSign-in with MFA satisfied, from a first-seen device on a hosting provider network.
Mail from calder-freight.example is moved to Archive and marked read.
Please review the updated payroll document and sign in to confirm your details today.
Thanks for confirming. Please use the updated account below for this and all future payments.
“The mark of a great email security system is that we don’t have to manage it. … It’s put a stop to the increasing number of attacks – even those using compromised infrastructure and AI to customize attacks to specific employees.”

Behind that one finding, one agent per signal, weighed together per account.
Most of it. Token theft and adversary-in-the-middle kits get past it, so behavior after the login is the remaining tell.
Impossible travel, new devices, inbox rule changes and suspicious internal sends, weighed together per account.
Not today. Every finding comes with recommended steps, and your team acts in Entra ID, Okta or Google Workspace. Automated containment is next.
The same API connection as inbound, plus audit-log access. On Microsoft 365, sign-in reports need Entra ID P1.
Early access runs on the connection you already have, review-only, with no MX change.
Connect a tenant, run in monitoring mode, and compare against what your current stack delivered.