We’re excited to announce AI-powered anomaly detection enhancements designed to catch the sophisticated attacks that traditional rules-based techniques miss.
The Challenge We’ve Solved
Improbable travel detection is effective at catching attackers who move between distant locations at unrealistic speeds. However, cybercriminals increasingly use VPNs and anonymizers to hide their true locations. These zero-velocity hijacks – where the attacker appears to be in the same location as the legitimate user – have remained difficult for traditional detection methods to identify.
Real-World Impact
In validation testing, the enhanced system detected attack scenarios commonly leveraged by adversaries to compromise critical M365 and Azure identity, closing gaps that rules-based detection capabilities alone could not. Using behavioral anomalies alone – we have introduced capabilities to identify and remediate anomalous session events even when sophisticated anonymizer and obfuscation techniques are used by an attacker.
What This Means for Your Security
This enhancement expands detection coverage while minimizing operational overhead. By combining existing rule-based precision with enhanced AI-powered pattern recognition, we can now catch sophisticated session hijacking attempts that use evasion techniques commonly associated with advanced threat actors.
The system runs automatically in the background and requires no configuration changes, providing enhanced protection against a variety of M365 threats.
Available now for all Adlumin customers.