Autonomous Hunter

Invisible LDAP Spike. Detected in Minutes.

16,052
LDAP queries in 5 hours, ~100x normal baseline
166
Normal baseline, queries/day from GitLab EKS node
16,052
Spike, queries over 5 hours on Feb 19
780
Users added to OU, Feb 16-19, triggering identity sync
Low
Risk outcome, benign, flagged for IAM team verification

The problem

A 100x spike that looked exactly like LDAP enumeration reconnaissance.

The Autonomous Hunter flagged a 100x surge in LDAP queries from a GitLab EKS node — indistinguishable from LDAP enumeration — and traced it to a legitimate OU expansion within minutes.

No Rules Required

Traditional SIEM rules would never flag this. There is no signature for "your OU grew by 780 users and triggered an identity sync." Behavioral anomaly detection catches statistical deviations that rule-based systems cannot see by design.

Automated Root Cause

The Autonomous Hunter traced the surge to a specific OU expansion — 780 users added to a managed users OU between Feb 16-19 — correlated with a dev build push, and identified the GitLab EKS sync job as the trigger. All in minutes.

Real Visibility

This time it was benign. Next time the same signature could be active LDAP enumeration reconnaissance. Either way, you know immediately — with full context. That is the difference between monitoring and actual detection.

The lesson

Benign behavior — but indistinguishable from LDAP enumeration without deep context. The Autonomous Hunter provided that context in minutes, not analyst hours.

Contact us for a 30-day POV
on your own directory traffic.

Book a Demo
Or reach us directly at hello@alphalevelsec.com  ·  alphalevel.ai