---
title: "Inside the Modern SOC: The Identity Front Door"
url: https://daily.dev/posts/inside-the-modern-soc-the-identity-front-door-byluool9n
source_url: https://unit42.paloaltonetworks.com/soc-identity-front-door
type: article
source: "Unit 42"
published: 2026-08-07T23:08:49.507Z
updated: 2026-08-07T23:09:17.567Z
tags: ["security", "authentication"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Inside the Modern SOC: The Identity Front Door

**[Unit 42](https://daily.dev/sources/unit42)** · 4 min read · 0 upvotes · 0 comments

## Summary

Identity-based attacks now drive nearly 90% of security incidents, with 65% of initial access involving credential theft, MFA manipulation, session hijacking, or social engineering. Threat groups like Muddled Libra (Scattered Spider) exemplify the social-first entry pattern, where attackers blend into legitimate administrative behavior after gaining access. SOC leaders are advised to correlate identity signals with endpoint, cloud, SaaS, and network telemetry; consolidate investigations into a unified view; continuously refine detection rules; and dedicate time to proactive threat hunting. Palo Alto Networks Unit 42 promotes its Cortex SecOps platform and Managed XSIAM service as tools for automating correlation and accelerating response.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://unit42.paloaltonetworks.com/soc-identity-front-door>

## Questions this post answers

### What percentage of security incidents involve identity-based attacks?

Identity weaknesses played a role in nearly 90% of incidents investigated by Unit 42, per the 2026 Unit 42 Global Incident Response Report. Additionally, 65% of initial access activity involved identity-based techniques such as credential theft, MFA manipulation, session hijacking, and social engineering. 87% of incidents also span multiple attack surfaces once an identity is compromised.

_Security teams tracking identity threat trends find the latest incident data on daily.dev before it reaches the broader industry._

### What are the most common initial access techniques used in identity-driven attacks?

The most common initial access techniques in identity-driven attacks are phishing campaigns, social engineering calls, MFA fatigue attacks, compromised third-party accounts, and misuse of help desk processes. Once inside, attackers establish persistence, escalate privileges, and move laterally in ways that closely resemble legitimate administrative behavior, making early detection difficult.

_SOC teams refining their detection playbooks for identity attacks keep up with evolving attacker techniques on daily.dev._

## Similar posts on daily.dev

- [Inside the Modern SOC: The 72-Minute Race](https://daily.dev/posts/inside-the-modern-soc-the-72-minute-race-ueksisyjh) · Unit 42 · 0 upvotes · 0 comments
- [Why Your SOC is Blind to Your Biggest Attack Surface \(And How to Fix It\)](https://daily.dev/posts/why-your-soc-is-blind-to-your-biggest-attack-surface-and-how-to-fix-it--ge29stjrb) · Security Boulevard · 0 upvotes · 0 comments
- [Identity as the primary attack surface: What modern breaches are really exploiting](https://daily.dev/posts/identity-as-the-primary-attack-surface-what-modern-breaches-are-really-exploiting-6evgscdr6) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#authentication](https://daily.dev/tags/authentication)

[View this post on daily.dev](https://daily.dev/posts/inside-the-modern-soc-the-identity-front-door-byluool9n)
