Field notes · 20 January 2026

Auth anomalies worth ranking above volume noise

Authentication events are dense. Ranking which anomalies matter keeps application security analytics focused on account takeover risk.

Close view of a lock and key suggesting authentication security

Login volume alone rarely tells a useful story. A marketing campaign can double successful authentications overnight. Rank anomalies by how closely they resemble account takeover patterns: password spray shapes, impossible travel relative to session reuse, sudden MFA bypass attempts, or privilege elevation shortly after first login.

Correlate application auth events with password-reset and session-revocation messages. Attackers often chain these steps; analytics that treat each stream in isolation miss the narrative.

Watch for success after repeated failure from the same identity, especially when the success arrives from a different client fingerprint. That pattern deserves a higher rank than raw failure counts from a flaky mobile client.

When you present findings to application owners, lead with ranked scenarios and the events that support them. Volume charts help later; ranked stories help decisions now.

← All field notes