
Learn how to effectively investigate, contain and remediate this incident by following our
Response Playbook.
Anonymized Login incidents occur when an account within EntraID authenticates from anonymized infrastructure, such as VPNs, proxy servers, or the TOR network.
This incident is only detected if you have integrated Microsoft Entra ID with Lumu, check out our
integration guide.
Even though your organization’s users can use VPNs and proxy servers for legitimate purposes, such as remote work, threat actors heavily rely on these tools to orchestrate attacks. By routing their traffic through external or multi-hop proxies, adversaries can manage command and control (C2) communications and perform damaging activities without exposing their actual infrastructure or geolocation. An anonymized login is rarely an isolated event; it strongly indicates compromised credentials and serves as the entry point for a broader attack sequence. Identifying this behavior early is critical to stopping an adversary before they can establish a foothold and cause significant disruption.
By detecting this anomalous activity, Lumu provides valuable insight into the following critical areas:
- Identification of compromised credentials: Alerts security teams that an authorized user has successfully authenticated using an IP concealer. This allows organizations to intervene before the attacker can harvest sensitive data from online storage accounts and databases.
- Prevention of lateral movement: Detects when attackers attempt to use an anonymized connection to blend in with normal network traffic. This visibility allows defenders to stop adversaries from leveraging a compromised identity to access internal file shares, map network drives, or launch Remote Desktop Protocol (RDP) sessions.
- Mitigation of privilege escalation: Highlights malicious attempts to probe the Active Directory environment. This helps prevent attackers from executing attacks against Domain Controllers, scraping memory for credential hashes, or exploiting misconfigurations to affect systems with higher clearance.
This document outlines how the Lumu Portal delivers valuable insight into the detection of this attack by providing the necessary context—Scope, Severity, and Source—presented in a narrative that supports your response team's decision-making.
Collected Data
Through its integration with Microsoft Entra ID, Lumu is capable of collecting the user contextual data to provide a full picture of the normal behavior of the user alongside the recent log activity to map the attackers actions during the session.
Incident Details
The Lumu Portal delivers the collected data to facilitate rapid triage and decision-making. The data is displayed as follows:
1. Summary: This section highlights critical information, including the First and Last Logins and the Incident Duration. This data establishes a general scope of the incident, allowing analysts to quickly differentiate between a momentary anomaly (like a user traveling) and a sustained account takeover attempt.
2. Targeted User: This section delivers crucial context about the specific user involved, capturing the user's details exactly as they were at the time of the last detected event.
- Identity and Role: Shows the user's name, email address, and their specific job title and department (e.g., Marketing Director | Marketing and Communications). This information helps determine the potential impact or data exposure based on the user's clearance level.
- Security Posture: Highlights the account's authentication security, with a green MFA Enabled badge. This is vital for understanding how an attacker might be operating, if MFA is enabled, the attacker may have used session hijacking or an MFA fatigue attack to access the account bypassing security measures.
- Account Groups: An list showing all the organizational Active Directory groups the user belongs to (e.g., news, IT, All Company). By knowing the user's access rights, you can understand the potential scope in case the compromised account is used to move laterally across the network.
3. Anonymized Login Activity: This section provides a comprehensive overview of the specific login events originating from the targeted user. It is divided into three key areas to help investigate the context and severity of the obfuscated session:
Muting anonymized login alerts
You can customize which alerts you receive by muting specific users or approved VPN vendors. Once configured, anonymized activity from these trusted sources will no longer trigger an incident, ensuring your incident response queue remains reserved exclusively for unauthorized anonymized infrastructure that indicate potential account takeovers. This is especially useful if you have authorized VPN vendors which certain users of your organization use, or there are certain users who are authorized to use VPNs due to their working conditions.
You can customize Anonymized Login alerts from the Lumu Portal by doing the following.
1. Enter the details of an Anonymized Login incident that has a user/user group or VPN you would like to exclude from the incident alerts.
2. Go to the Take Action menu on the right and select Close incident.
3. In the Close Incident modal select Advanced options.

4. Now, you will need to select the User Scope and the Anonymized Activity Scope to mute the alerts. In the User Scope dropdown, you will have the following options, select the one that best fits your needs.
- Mute only the user - useful when the user is authorized to use VPNs.
- Mute a specific account group - useful when there is an entire group that requires VPNs to perform their work.
- Mute all users in the organization - Select this option only if you do not want to be alerted about this detection.
5. If you selected the Mute a specific account group option, you will be prompted to select the account group you wish to leave out of the alerts.
This option only displays the groups related to the user involved in the incident.
6. Having selected the user scope, you can customize the anonymized activity to leave out the alerts. You can choose from:
- Mute a specific VPN Vendor - Best used when your organization has an authorized VPN vendor.
- Mute any anonymized activity - Use only if the users selected do not require anonymized activity monitoring.
7. Selecting Mute a specific VPN Vendor prompts you to select the VPN you wish to leave out of the alerts.
8. Once you complete your desired customization, you can click Close Incident to save changes.
In case you require to remove some of the muting rules you have created, contact our support team.
Incident data export
While the Lumu Portal displays the most critical data points—such as the top attacking sources and target users—complex attacks often involve volumes of traffic that exceed what can be efficiently displayed on a single screen. For that reason, the Lumu allows in-depth investigations with its Export Feature. It allows analysts to move beyond the high-level summary and access the complete forensic dataset of the incident.
You can export data using the dropdown menu located at the top of the page (1).
Exportable data
You can export the following data for this incident:
- All anonymized events
Generates a csv file with the information of every anonymized login event recorded in the incident. - Single event context
Generate a csv file with the context information of a single login event recorded within an incident (2).