VeUP
← All case studies
Security · Threat Detection & Response
Invisory wordmark

Invisory contains 3 former-insider access events on AWS, app back same week

AdvisoryIncident response & containmentAudit-log forensicsIdentity federation & MFA enforcementMulti-tenant isolation
3
insider-access events contained
Week one
the offline application brought back
Durable
tenant separation + MFA-gated federation — no way back in
AWS IAMAWS CloudTrailIAM Identity Center

During an active former-insider access incident, VeUP delivered AWS-native incident response for Invisory, a B2B SaaS platform — cross-app access revocation, AWS CloudTrail audit forensics, identity-tenant separation, and MFA-gated federation. Three access events contained, the app restored in week one.

The challenge

During onboarding, Invisory faced an active incident in which a former insider retained access across connected applications. The production application was taken offline, legitimate internal users had been deleted, and overlapping identity paths through a single shared production/staging tenant allowed access to be regained — requiring immediate containment, recovery, and durable identity hardening against recurrence.

The solution

AWS-native incident response delivered from day one of onboarding. VeUP revoked access across every connected application against a verified leaver list; ran AWS CloudTrail audit-log forensics and confirmed logging coverage across the AWS account; recreated legitimately deleted internal users and restored the offline application; separated the identity environment from one shared production/staging tenant into isolated production and staging tenants to eliminate the overlapping paths; and re-established MFA-enforced federated access (AWS IAM Identity Center / federation) as the durable control. Production compute runs on Amazon EC2 across multiple regions, with AWS IAM, Amazon SNS, and cost allocation in support.

Production outcomes

KPIResult
Production outcomesThree separate former-insider access events were contained over the engagement — the initial takedown, an admin/staging push-path recurrence, and a staging-tenant compromise. The offline production application came back within the first week of onboarding, with legitimate users recreated. The identity environment moved from one shared production/staging tenant to isolated production and staging tenants, AWS CloudTrail coverage was confirmed, and MFA-gated federated access returned as the durable control.
Engagement windowIncident response began on day one of onboarding in May 2025. A recurrence in mid-June was contained, and the staging-tenant separation completed in early July 2025.
Cost / TCO postureNot a cost-optimization engagement — value is containment, same-week recovery, and durable identity hardening. AWS Cost Allocation was used in support; no realized-savings claim.
Lessons & continuationOverlapping production/staging identity paths are how revoked access gets regained — tenant separation is the durable fix, not just re-revocation; revoke against a verified leaver list across every connected application; confirm CloudTrail coverage and re-establish MFA-gated federation as the standing control.
AWS services in production
AWS IAMAWS CloudTrailAWS IAM Identity Center / federationAmazon EC2Amazon SNS

Architecture

The engagement in one picture: the compromised, single shared production/staging identity tenant on one side, the remediated AWS target state on the other — isolated production and staging tenants, MFA-gated AWS IAM Identity Center federation, a cross-application access-revocation boundary, and AWS CloudTrail forensics.

Target-state AWS architecture: isolated production and staging tenants each running Amazon EC2, MFA-gated AWS IAM Identity Center federation, a cross-application access-revocation boundary spanning AWS IAM, the SSO layer, and the endpoint-protection console, AWS CloudTrail audit-log forensics, Amazon SNS notifications, and AWS Cost Allocation.
The remediated estate — isolated identity tenants, MFA-gated federation, and one revocation boundary spanning every connected application.
Previous-state architecture: the compromised, single shared production/staging AWS identity tenant with a federated SSO layer (Auth0 / Google SSO) on AWS IAM, connected applications retaining former-insider access, and no cross-application revocation boundary.
Where the incident started — one shared production/staging identity tenant, as VeUP found it.