# Identity Compromise Investigation Worksheet

Identity: __________  Incident ID: __________  Analyst: __________

## Establish normal

- Expected owner, role, privileges, devices, locations, applications, and working hours:
- Authentication methods and enrolled recovery methods:
- Service dependencies or non-human use:

## Investigate

- [ ] Sign-ins, failures, risk signals, session creation, and token use
- [ ] MFA registration, reset, bypass, fatigue, and method changes
- [ ] Password, key, certificate, secret, cookie, and token exposure
- [ ] Privilege, role, group, delegation, consent, and trust changes
- [ ] Mailbox rules, forwarding, OAuth grants, application registrations, and persistence
- [ ] Endpoint activity immediately before and after suspicious authentication
- [ ] Access to sensitive data, control planes, repositories, or backups
- [ ] Related identities, source infrastructure, user agents, and devices

## Response

- Containment action and UTC time:
- Sessions/tokens revoked:
- Credentials/secrets rotated:
- Persistence removed:
- Business owner validation:
- Monitoring period and exit criteria:
