Skip to content
Skip to main content
Accounts & Identity Operational Explainer

How can I distinguish the genuine user from an intruder?

Do it event by event.

Once an account is compromised, one account history may contain actions from the genuine user and the intruder at the same time.

The job is to separate those sessions and then see which person each event fits.

Build a known-good baseline first

Start with activity you can confidently connect to the genuine user.

That may include:

  • their usual device;
  • normal working hours;
  • known locations;
  • long-standing sessions;
  • familiar applications;
  • previous account behaviour; and
  • confirmed security factors.

Then mark the first new or suspicious elements:

  • unfamiliar device;
  • new session;
  • new source network;
  • recovery change;
  • password reset;
  • new MFA factor;
  • or unusual application.

Segment the activity by session

A useful working table might be:

Time Session Device/client Activity Initial view
08:20 S-100 Known iPhone Normal messages Genuine baseline
09:11 S-4812 Unknown browser New login Suspicious
09:14 S-4812 Unknown browser Recovery changed Suspicious
09:32 S-100 Known iPhone Holder checks account Genuine
09:36 S-4812 Unknown browser Payment details changed Suspicious

This immediately shows why “everything after 09:11 was the intruder” may be too crude.

Add independent evidence

Behaviour alone is rarely enough.

Use other sources such as:

  • device possession;
  • CCTV;
  • building access;
  • location;
  • other-platform messages;
  • financial activity;
  • phishing or malware evidence;
  • notifications; and
  • communications with the provider.

If the suspicious session is active from a device recovered elsewhere while the genuine user's phone continues its normal activity, the separation becomes stronger.

Do not overvalue writing style

Language, spelling and contacts may support the picture, but people change tone and intruders can imitate behaviour.

Use those features as supporting context rather than the whole attribution.

SessionWhich technical route?Separate concurrent account access.
DeviceWhere did it operate?Known or unfamiliar handset/browser.
ContextWho controlled it?Location, possession and wider evidence.

The practical point is: separate the account history into sessions first, then attribute each important event using device and independent evidence. Some events may remain open even when the takeover itself is clear.

Reference: AI-028Accounts & Identity