Identifying suspicious credential usage
How NCSC guidance can help organisations detect and protect themselves from credential abuse.
Our advice & guidance covers a broad range of topics
Resources for individuals and organisations in the UK who have experienced an online scam or cyber attack.
Find a range of products & services from NCSC and certified 3rd party suppliers
Working with industry, government and academia to support the next generation of researchers, students and cyber security professionals
All the latest information to help you keep track of what's happening
How NCSC guidance can help organisations detect and protect themselves from credential abuse.

This content was last reviewed on 05/03/2025
The use of compromised credentials is still behind a large proportion of incidents that the NCSC responds to, regardless of the sophistication or attribution of the threat actor. This blog-post, which is for technical staff and system owners, suggests some actions to identify potentially suspicious behaviours associated with the replay of compromised (but legitimate) credentials.
The actions below draw from the NCSC's Identity and Access Management, Managing User Privileges (from our 10 Steps to Cyber Security) and Protecting Management Interfaces guidance. They all highlight the importance of:
As atomic indicators, such as the malicious infrastructure or malware samples used can vary even between individual victims of the same threat actor, we recommend taking the following steps to identify potentially suspicious behaviours associated with the replay of compromised but legitimate credentials.
1. Identify what privileged accounts exist in your environment, particularly (but not exclusively) those used by third party providers or vendors. Experienced users can use tools such as Bloodhound to identify accounts especially valuable to an attacker.
2. Determine what ‘normal’ looks like, for those accounts, using sources such as existing logging or configuration documents. This will include:
• typical access IP addresses (including those that are internal to your network and external)
• typical source hostnames (where this data exists in your logging)
• common working hours (frequency of use, and whether the activity is automated)
• types of activity or systems accessed by those accounts
3. Assess for activity outside of those expected norms.
4. Reset or lock accounts where there is concern.
5. Investigate for further compromise as a result of any accounts flagged as suspicious.
If you’re supporting a Microsoft environment, we also recommend you read their targeted advice for incident responders on recovery from systemic identity compromises.
Of course, most of us allow third parties some sort of access (especially with cloud services), so there are scant systems where credentials are only used by the organisation. Service/machine credentials are just as important as people’s. Monitoring for unusual use of credentials on your system not only helps you to mitigate insider risk and detect compromise of your own estate, it also helps you detect if someone in your supply chain has breached some of your credentials, as per the recent SolarWinds (and related to that, Mimecast) incidents.


