Written rules, not hunches
Every type of event has its rule and its threshold. Reuse of a session token opens a critical incident immediately, with no counter. More than five 2FA failures in a minute, for one user or from one address: high-severity incident. More than ten login failures in a minute from the same address: incident. An API key used from an address never seen before: incident, to be confirmed.
- Session reuse: critical, immediate, all sessions revoked
- Burst of 2FA failures or 2FA activation failures: high
- Burst of login failures from the same address: monitored
- API key from a new IP address: flagged