Account takeover detection from live provider signals
Centeye consumes the identity providers’ own event streams and calls the takeover from the signals that carry it:
- Risky sign-ins & impossible travel — a login from two countries an hour apart, a token used from the wrong device, a pattern that breaks the user’s established history.
- MFA-fatigue detection — repeated push-prompt bombardment engineered to extract a tired “approve.”
- Session hijacking & token-theft (AiTM) signals — replay and adversary-in-the-middle indicators read from the identity provider.
- Malicious inbox rules — the forwarding and delete rules attackers plant for persistence and fraud cover.
- Rogue OAuth app detection — third-party grants quietly given access to mail and files: the persistence layer of a modern takeover.
- Credential exposure — monitoring for leaked and infostealer-harvested credentials tied to the tenant.
live IdP streams · Entra ID + Google Workspace