Skip to main content

Review identity activity analysis results

Use this article to get an understanding of reviewing the identity activity analysis results and what details are displayed.

After an analysis runs, the Identity Activity Details page shows a summary of the investigation scope and a timeline of all identity activity in the selected window.

Scope bar

The bar at the top of the results page shows the parameters of the current analysis:

Field

Description

Selected Identity

The identity that was analyzed.

Identity Type

User or Service Principal.

Source

The identity provider (Entra ID, Microsoft Active Directory, or Okta)

Start Date

Start date and time of the investigation window.

End Date

End date and time of the investigation window.

  • Click New Analysis to change the identity, provider, or time range and re-run the analysis.

  • Click Analysis History to view or reopen any previously created analyses.

Activity summary

Below the scope bar, the Identity Activity Details section shows event counts grouped by MITRE TTPs. Select any tile to filter the activity timeline to that tactic only.

Tile

Description

Total Events

All events recorded for this identity in the investigation window.

Changed Objects

Objects that were created, modified, or deleted.

Persistence

Events related to techniques attackers use to maintain access to the environment.

Privilege Escalation

Events related to techniques attackers use to gain higher privileges or permissions.

Defense Evasion

Events related to techniques attackers use to avoid detection or bypass security controls.

Credential Access

Events related to techniques attackers use to steal or obtain credentials such as passwords, tokens, or keys.

Impact

Events related to techniques attackers use to damage, disrupt, or affect systems and data.

Activity timeline-graph view

The default view is the activity graph. It shows identity objects as nodes and actions as labeled edges, arranged on a horizontal time axis.

  • Row labels on the left identify the object type: Users, Groups, Administrative Roles, Service Accounts, Service Principals, Enterprise Applications, Authentication Methods, Devices.

  • Edge labels show the action type: Create, Modified, or Delete.

  • Events at the same timestamp in the same object-type row are grouped vertically to reduce clutter.

  • Each event is color-coded by severity.

  • Use the forward and backward arrows next to the date range to scroll the timeline horizontally.

Activity timeline-list view

Select the table icon to switch to the list view. Each event appears as a row:

Column

Description

Time

Timestamp when the event occurred.

Actor Identity

The identity that performed the action.

Activity

The specific action (for example, Add user, Update group, Add eligible member to role).

Target Identity

The identity or object that was affected.

Action

Create, Modified, or Delete (color-coded pill)

MITRE TTPs

The mapped MITRE ATT&CK technique and tactic (for example, T1098.003 – Privilege Escalation)

The count above the table shows how many activities are displayed out of the total.

You can filter the list by Activity Type, Severity, MITRE TTPs , and Target Identity Type.

Export identity activity analysis data

  • Analysis header: Selected Identity, Identity Type, Source, Start Time, End Time

  • One row per event: Time, Actor Identity, Actor Identity Type, Activity, Target Identity, Target Identity Type, Action, MITRE TTP, Action Severity.

Next step

When you have identified the scope of the compromise, click View Cyber Recovery Plan to begin recovery. See Build a guided recovery plan.

Did this answer your question?