# Solutions UPDATE.1 2026

# We triage what other platforms can't

Other AI SOC platforms have coverage ceilings. They rely on pre-defined logic and follow fixed triage questions.
Radiant uses a structured 5-step investigation process designed to handle any alert, from the common to the complex.

[Book a Demo](https://radiantsecurity.ai/book-a-demo/)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Solution-page-hero-large2.png)

Other AI SOC platforms have coverage ceilings. They rely on pre-defined logic and follow fixed triage questions.
Radiant uses a structured 5-step investigation process designed to handle any alert, from the common to the complex.

[Book a Demo](https://radiantsecurity.ai/book-a-demo/)

# Triage any alert with Radiant’s
5-Step Methodology

# The triage process: What we do

Radiant follows the same investigative flow a human analyst would: understand → enrich → plan → execute → conclude.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Classification.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Classification

AI interprets the characteristics of a raw alert to determine it’s type of threat, and understand whether it has encountered it before. This determines if a plan will be re-used or generated from scratch in step 3.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Enrich.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Enrich.svg)

### Enrich

AI automatically pulls in context from across your environment: threat intelligence, identity data, asset information, and more, so your team has everything they need to make a decision without manually stitching data together.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/12Classification.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Plan.svg)

### Plan

AI plans the structured set of steps that determines exactly how the alert will be investigated. Plans are built dynamically based on: Radiant’s expert knowledge, your unique environment, and context memory.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Execute.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Execute.svg)

### Execute

AI runs automatically to answer each investigative question, pulling information from your connected security tools, SIEMs, and external data sources without any manual effort from your analysts.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Conclude.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Conclude.svg)

### Conclude

AI provides a transparent verdict by weighing malicious indicators against benign ones. Once analysts review and validate the reasoning of escalated alerts, they can group related alerts into a case, where they can view the full threat picture and take action from a single place.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Line-8.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Classification

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Classification.svg)

AI interprets the characteristics of a raw alert to determine it’s type of threat, and understand whether it has encountered it before. This determines if a plan will be re-used or generated from scratch in step 3.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Enrich

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Enrich.svg)

AI automatically pulls in context from across your environment: threat intelligence, identity data, asset information, and more, so your team has everything they need to make a decision without manually stitching data together.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Plan

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/12Classification.svg)

AI plans the structured set of steps that determines exactly how the alert will be investigated. Plans are built dynamically based on: Radiant’s expert knowledge, your unique environment, and context memory.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Execute

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Execute.svg)

AI runs automatically to answer each investigative question, pulling information from your connected security tools, SIEMs, and external data sources without any manual effort from your analysts.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/1Classification.svg)

### Conclude

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Conclude.svg)

AI provides a transparent verdict by weighing malicious indicators against benign ones. Once analysts review and validate the reasoning of escalated alerts, they can group related alerts into a case, where they can view the full threat picture and take action from a single place.

# The output for analysts: What you see

See how we deliver the details that matter the most once triage is completed.

Click through to see examples of each alert type.

WAF WAF WAF WAF WAF WAF WAF WAF WAF WAF WAF WAF

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon.svg)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/malicious-Stroke.svg)

Recommended Malicious

Suspicious VPN login bypassed MFA on registered device

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon-source.svg)

Escalate to Case

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon987.svg)

Classification

Anomalous VPN Login

Employee’s account was accessed from an unfamiliar location behind a consumer VPN — MFA challenges failed three times, and no ZTNA client was found on their registered device.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon765.svg)

Planning and Execution

AI triage findings

**Is the login IP associated with a VPN or anonymizing service?**

The IP resolves to an ExpressVPN exit node in Iceland — absent from this user’s entire login history.

**Did the user successfully complete MFA during this login?**

MFA failed three times — session access was granted via a legacy authentication fallback policy.

**Is a VPN client installed on the user’s registered endpoint?**

No VPN client is installed on the registered device — confirming the VPN traffic originated elsewhere.

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon54654.svg)

Enrichment

Involved artifacts

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

srodriguez@blastlabs.com

authenticated via desktop browser

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector-Stroke.svg)

Remote Azure AD — MFA: Failed

originating from commercial VPN exit node

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

104.223.87.34 (Reykjavik, Iceland)

flagged against registered device baseline

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector876Stroke.svg)

srodriguez-DELL-WIN11

with prior clean login pattern from expected location

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/Vector45Stroke.svg)

76.102.44.19 (Austin, Texas)

![](https://radiantsecurity.ai/wp-content/uploads/2026/03/icon65765.svg)

Response

Take action

Suspend user account

Microsoft Entra ID

Terminate active sessions

Microsoft Entra ID

Force MFA re-enrollment

Microsoft Entra ID

## What security leaders say?

From the first day of the POC, Radiant was catching things our MSSP was missing. Their platform is the most accurate agentic SOC we’ve seen, with investigations going significantly deeper than anything else we looked at.

Brian Rowe

Vice President Information Technology

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Brian-Rowe.webp)

Most organizations can bring their SOC in-house today thanks to AI SOC. Validating alerts is simpler than it used to be, and pulling log data into a single view means you're not searching through multiple systems.

Rodney Stewart

Infrastructure Engineering and Security Manager

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Video-Container-2.webp)

“Radiant Security consistently goes above and beyond to adapt to our specific security needs, their leadership team is closely involved, and every custom request is taken seriously and delivered in a short time”

Josh Lanners

Director, IT Ops and Security

![](https://radiantsecurity.ai/wp-content/uploads/2026/01/Video-Container.webp)

“Radiant cuts through the ambiguity of traditional managed security. It provides the deep context and speed we need, often alerting us to threats well before a manned SOC. Getting detailed, correlated information in a sensible manner, and getting it quickly, makes my job a lot easier.”

Rob Boyd

Manager of information security

![](https://radiantsecurity.ai/wp-content/uploads/2026/02/Group1707480925.webp)

“Thanks to Radiant, we can now focus on our customer's real threats instead of drowning in alert noise.”

Gregory Morawietz

Owner

"Our mean time to detect is 10X better than the industry average, and our mean time to respond is 2X better. We're saving between 200-300 hours a month.

![Michael_Butler](https://radiantsecurity.ai/wp-content/uploads/2023/08/Michael_Butler-150x150.jpg)

Michael Butler

Director of Information Security Operations

”As much as I would like to keep Radiant a secret for my own competitive advantage, I would definitely recommend it to any MSSP who is serious about their cybersecurity.”

Grigoriy Milis

CIO
