Skip to content
Skip to main content
Cyber Incidents & Offender Methods Operational Explainer

What evidence may show the point at which control changed?

Look for a cluster of authentication, session, device and security events that marks the transition from known legitimate use to suspicious control.

The visible fraud or disruption may happen later. The useful point is often the earliest supported change in effective control.

Look before the obvious consequence

Useful events include:

  • new session or client;
  • unfamiliar device;
  • recovery change;
  • password reset;
  • new MFA factor;
  • forwarding rule;
  • application consent;
  • new administrator;
  • unusual API activity;
  • behavioural shift.

A control timeline might look like:

Example control-change window
08:14 · known user session active08:31 · unfamiliar client authenticates08:34 · recovery email changed08:36 · new MFA factor enrolled08:41 · disputed forwarding rule created

That may support a control-change window of roughly 08:31–08:36 rather than waiting until the later fraud is noticed.

Geography alone is weak

VPNs, mobile networks and corporate proxies can make ordinary activity look unfamiliar.

Prefer combinations such as:

  • new device + new factor;
  • new session + recovery change;
  • unfamiliar client + account-security change;
  • suspicious session + disputed activity.

Bound restoration as well as loss

The other end matters too.

Record:

  • password reset;
  • session revocation;
  • factor removal;
  • account recovery;
  • confirmed return to legitimate control.
Known-goodLegitimate controlNormal device, session and factors.
TransitionControl-change eventsAuthentication/security state begins to change.
Unauthorised periodDisputed account activitySession and account events define the window.
RestorationContainment/recoveryControl returns or access is revoked.

Exact timing may remain uncertain. If so, report a supported window rather than invented precision.

The practical point is: reconstruct control as a bounded timeline from converging account and user evidence. The earliest obvious fraud is not necessarily the moment control changed.

Reference: CIM-058Cyber Incidents & Offender Methods