Detections
Describe the threat in plain English — icite builds and tunes the detection, correlating events, config history, and the identity graph across every provider. Catch the cross-provider attacks no single rule can see.
The backlog is the vulnerability
Custom detections queue behind engineering sprints. By the time the correlation rule ships, the departing employee already left — with the customer list.
Your SIEM sees events, not identities
A log line can't tell you that a group change three months ago quietly made someone a shadow admin today. That answer lives in config history and the graph — layers most tools never ingest.
Every provider is a silo
Okta sees the sign-in. AD sees the group add. Google sees the share. Nobody sees the actor. Cross-provider correlation is the whole game — and writing it by hand doesn't scale.
How they work
Value on day one
We build and maintain detections everyone can use. Copy them, customize them, or let them run as-is.
Privilege escalation
Nested-group escalation paths
Group-in-group chains that quietly end at a privileged role — traversed across the graph, not eyeballed in a console.
Toxic combination
Departing-employee exfiltration
Salesforce report export + GitHub repo clone + heavy Drive access, in the run-up to a termination date in your HRIS.
Trust abuse
Federation & trust abuse
New or altered federation trusts and the access they unlock downstream — correlated across IdP and cloud IAM.
Posture drift
Shadow admins from past changes
Admin-equivalent access introduced by a config change months ago. Temporal snapshots catch what today's scan can't.
Account hygiene
Dormant-account reactivation
An account that slept for ninety days signs in from a new ASN. Point-in-time tools see a login; icite sees a resurrection.
Lifecycle gaps
Offboarding lag & NHI ownership
Access that outlives employment, and service accounts nobody owns. The graph knows who should have been gone.
For the people who own the risk
Fewer false positives over time triage verdicts feed tuning by design; the signal loop is never optional.
Temporal, not point-in-time replay any identity's history to show exactly what changed, when, and what access it unlocked.
Works with your stack output feeds your SIEM/SOAR; detections cover the identity layer your XDR doesn't.
MTTD you can measure every detection reports run cadence and time-to-finding.
Okta
Entra ID
Active Directory
LDAP
AWS IAM
Workday & HRIS
IGA
Google Workspace
Salesforce
GitHub

