I have been given an account or username
Treat the account as a collection of provider, session, device and activity records. An account name may identify the service record without identifying the person who controlled each event.
Start with what needs doing now
Use this route to preserve the account context, identify useful provider records and test genuine use against compromise.
Move from the visible account to identifiers, provider records, sessions, devices and defensible attribution.
Reference AI-000Provider evidenceWhat records might the provider hold?Identify registration, login, device, recovery, session and activity records that may exist beyond the visible profile.
Reference AI-029Test compromiseGenuine user or intruder?Compare account, authentication, device and behavioural evidence before attributing disputed activity.
Reference AI-028Understand the evidence and the offender method
Use this route to understand what an account is, how control differs from registration and how an offender can exploit account access.
Understand the service-side record that connects identifiers, credentials, settings, sessions and activity.
Reference AI-001Separate offender exampleSee how Dodgy Dave exploits account accessFollow a separate offender method without confusing it with the investigator walkthrough.
Reference AI-031Go directly to the issue you need to resolve
Distinguish registration from practical control at the relevant time.
Reference AI-011Shared accessCould several people share the account?Test formal, informal and unauthorised access.
Reference AI-006AuthenticationWhat does a successful login prove?Use the event without overstating who performed it.
Reference AI-017Alternative explanationCould the account be compromised?Recognise takeover, stolen sessions and other access routes.
Reference AI-025Browse every Accounts and identity guidance page
The complete reference library remains available when you need a narrower question.- I’m interested in an online account. What can it tell me, and what should I do next?
- What is an online account?
- What information can an online account contain?
- Does an account identify a person?
- What is the difference between an account, a profile and a username?
- Can one person have several online accounts?
- Can several people share one account?
- Can an online account belong to a business or organisation?
- Can software or a device use an online account?
- Who is the registered account holder?
- Who created the account?
- Who controlled the account?
- Who was actually using the account?
- Who paid for the account?
- Who was responsible for the activity?
- What is authentication?
- What is multi-factor authentication?
- What does a successful login actually prove?
- Does a password prove ownership?
- Can someone log in without knowing the password?
- What is a session cookie?
- What is a login session?
- What is single sign-on?
- What is a trusted device?
- What does logging out actually do?
- What is an account compromise?
- What is account takeover?
- How do investigators recognise account takeover?
- How can I distinguish the genuine user from an intruder?
- What account records might a provider hold?
- What should I ask a provider for?
- See how Dodgy Dave exploits account access