Detections

Write the detection you

actually need. In minutes.

Write the detection you

actually need. In minutes.

Describe the threat in plain English — icite builds and tunes the detection, correlating events, config history, and the identity graph across every provider. Catch the cross-provider attacks no single rule can see.

Search...⌘K
Home
Detections
Findings
Reports
Timeline
Identities
Recent inquiries
Environment Investigation Complete...
Identifying Non IdP Managed Accounts
Getting started with Icite
VPN Usage Status Unknown
ISP Usage Last Five Days
View all
Shared with you
Agentic AI Activity Overview
Claude Code identities and delegat...
High Risk Users MFA Admin Access
Icite Throxy Employee Interaction...
Kevin Manson Application Access...
Finish onboarding 3/6
Icite
ty@icite.io
DetectionsDeparting actor — multi-platform exfil (toxic combination)
Clone
Revert to draft

Departing actor — multi-platform exfil (toxic combination)

Fires when a Workday-terminating employee (within ±termination_window_days of their termination_date) exhibits ALL of: (1) a Google Drive external-share rate spike vs their 90-day baseline, (2) a GitHub repo clone in the exfil window (optionally scoped to sensitive repos via sensitive_repo_pattern), and (3) a large Salesforce report export — AND has a graph-confirmed permission path to at least one of the resources they actually exfiltrated (the cloned GitHub repo or the exported Salesforce report, correlated by resource_id). High-precision by construction: the four-signal AND plus the access-to-the-exfiltrated-resource gate. Note the gate only fires when the exfiltrated resource is modeled in the identity graph, so resources absent from the graph won't corroborate.

det-6yhcgil24kytIdentityPublished
Overview
Logic
Run history
Findings
Suppressions
Total steps
15
Data sources
Events, Config, Graph
Last modified
Jul 21st, 10:47 PM UTC
STEP 1Terminating Workday actors with platform source IDs
STEP 2Drive external-share rate spike vs 90d baseline
STEP 3GitHub repo clones by terminating actors
STEP 4Large Salesforce report exports by terminating actors
STEP 5Terminating actors with Drive exfil spike
STEP 6Above + GitHub clone of sensitive repo
STEP 7All four exfil signals present
STEP 8All identities' graph-reachable resources (resource_id per path)
STEP 9Key accessible resources by canonical_id|resource_id
STEP 10Per-actor exfil target resource ids (repo + report)
STEP 11Split exfil target ids into an array
STEP 12One row per (actor, exfil target id)
STEP 13Key exfil targets by canonical_id|resource_id
STEP 14Actors with access to exfil target
STEP 15Toxic combination — exfil corroborated by access to the exfiltrated resource

Features

Features

Point-in-time detections miss the attacks that take their time.

Point-in-time detections miss the attacks that take their time.

The backlog is the vulnerability

Custom detections queue behind engineering sprints. By the time the correlation rule ships, the departing employee already left — with the customer list.

Your SIEM sees events, not identities

A log line can't tell you that a group change three months ago quietly made someone a shadow admin today. That answer lives in config history and the graph — layers most tools never ingest.

Every provider is a silo

Okta sees the sign-in. AD sees the group add. Google sees the share. Nobody sees the actor. Cross-provider correlation is the whole game — and writing it by hand doesn't scale.

How they work

From idea to detection in four steps.

From idea to detection in four steps.

01. Describe

02. Draft

03. Tune

04. Run

Say what you're looking for or just drop in a csv

Drag and drop threat intel, or describe the threat the way you'd brief an analyst. No correlation-query language, no schema spelunking.

01. Describe

02. Draft

03. Tune

04. Run

Say what you're looking for or just drop in a csv

Drag and drop threat intel, or describe the threat the way you'd brief an analyst. No correlation-query language, no schema spelunking.

Value on day one

25+ ready-to-go detections for the threats that live between your tools.

25+ ready-to-go detections for the threats that live between your tools.

We build and maintain detections everyone can use. Copy them, customize them, or let them run as-is.

Privilege escalation

Nested-group escalation paths

Group-in-group chains that quietly end at a privileged role — traversed across the graph, not eyeballed in a console.

Toxic combination

Departing-employee exfiltration

Salesforce report export + GitHub repo clone + heavy Drive access, in the run-up to a termination date in your HRIS.

Trust abuse

Federation & trust abuse

New or altered federation trusts and the access they unlock downstream — correlated across IdP and cloud IAM.

Posture drift

Shadow admins from past changes

Admin-equivalent access introduced by a config change months ago. Temporal snapshots catch what today's scan can't.

Account hygiene

Dormant-account reactivation

An account that slept for ninety days signs in from a new ASN. Point-in-time tools see a login; icite sees a resurrection.

Lifecycle gaps

Offboarding lag & NHI ownership

Access that outlives employment, and service accounts nobody owns. The graph knows who should have been gone.

For the people who own the risk

Detection coverage you can put in a board slide.

Detection coverage you can put in a board slide.

Fewer false positives over time triage verdicts feed tuning by design; the signal loop is never optional.

Temporal, not point-in-time replay any identity's history to show exactly what changed, when, and what access it unlocked.

Works with your stack output feeds your SIEM/SOAR; detections cover the identity layer your XDR doesn't.

MTTD you can measure every detection reports run cadence and time-to-finding.

Okta

Entra ID

Active Directory

LDAP

AWS IAM

Workday & HRIS

IGA

Google Workspace

Salesforce

GitHub

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc