What evidence may show the point at which control changed?¶
Look for a cluster of authentication, session, device and security events that marks the transition from known legitimate use to suspicious control.
The visible fraud or disruption may happen later. The useful point is often the earliest supported change in effective control.
Look before the obvious consequence¶
Useful events include:
- new session or client;
- unfamiliar device;
- recovery change;
- password reset;
- new MFA factor;
- forwarding rule;
- application consent;
- new administrator;
- unusual API activity;
- behavioural shift.
A control timeline might look like:
That may support a control-change window of roughly 08:31–08:36 rather than waiting until the later fraud is noticed.
Geography alone is weak¶
VPNs, mobile networks and corporate proxies can make ordinary activity look unfamiliar.
Prefer combinations such as:
- new device + new factor;
- new session + recovery change;
- unfamiliar client + account-security change;
- suspicious session + disputed activity.
Bound restoration as well as loss¶
The other end matters too.
Record:
- password reset;
- session revocation;
- factor removal;
- account recovery;
- confirmed return to legitimate control.
Exact timing may remain uncertain. If so, report a supported window rather than invented precision.
The practical point is: reconstruct control as a bounded timeline from converging account and user evidence. The earliest obvious fraud is not necessarily the moment control changed.