What is a service-account event?¶
A service-account event records activity under a non-personal identity used by software, an integration or an automated process. It identifies the account's technical authority, not an individual operator.
Service identities can act without a login ceremony¶
Applications and scheduled jobs may authenticate with stored passwords, certificates, API keys or managed identities. One service account can run continuously on several hosts and perform file access, database queries, network connections or configuration changes.
The account may be the intended identity for an automated function, or its credentials may have been used outside that function. Shared use across applications makes the event alone insufficient to identify which workload made the request.
Map the identity to its workloads and credentials¶
Establish the account's owner, purpose, permissions, authentication method and permitted hosts. Service configuration, scheduled jobs, credential history, application records and request or correlation IDs can link an event to a particular process.
Compare the source device, address, time and action with expected behaviour. If a person initiated a workflow, separate that initiating decision from the service account's later automatic actions. Attribution to misuse requires evidence about who controlled the relevant process or credential.
The point to remember
A service-account event identifies a technical identity; workload, trigger and credential evidence explain who or what used it.