Skip to main content

Identifying suspicious credential usage

How NCSC guidance can help organisations detect and protect themselves from credential abuse.

Decorative image of someone using laptop and 2FA

This content was last reviewed on 05/03/2025

The use of compromised credentials is still behind a large proportion of incidents that the NCSC responds to, regardless of the sophistication or attribution of the threat actor. This blog-post, which is for technical staff and system owners, suggests some actions to identify potentially suspicious behaviours associated with the replay of compromised (but legitimate) credentials.




Written by

Toby L Technical Lead for Incident Management