Skip to content

Latest commit

 

History

History
29 lines (17 loc) · 1012 Bytes

File metadata and controls

29 lines (17 loc) · 1012 Bytes

Suspicious Infrastructure Sharing

Scenario Summary

Several accounts share the same device identifier. One linked account has enforcement history, making the cluster useful for review and graph-based pivoting.

Telemetry Involved

  • Login events.
  • Device identifiers.
  • Enforcement records.
  • Generated case rows.

Detections Triggered

  • shared_infra.sql
  • shared_infrastructure.sql

Analyst Reasoning

The investigator starts from the subject user, pivots to the shared device, then reviews linked accounts and enforcement context. The graph helps make the relationship visible, while the timeline helps place the shared infrastructure events in sequence.

Escalation Decision

Shared infrastructure alone may not justify escalation; investigators should monitor for additional corroborating indicators.

Recommended Action

Use UNDER_REVIEW for isolated shared-infrastructure cases; use REFERRED if the case should be reviewed by another policy or platform-integrity specialist.