Conditional Access, Threat Intelligence, and the Attack and Threat Report

Analog Informatics Corporation (AIC) kits check every sign-in before it reaches a password. The check looks at where the request comes from, whether the address is on a threat intelligence list, and which sign-in policy applies. Blocked and failed attempts land in the Attack / Threat Report, mapped to MITRE ATT&CK.

These features are built into the AIC CMMC Completeâ„¢ Level 1, Level 2, and Level 3 kits. In industry terms they cover conditional access, Identity Threat Detection and Response (ITDR), and Identity Security Posture Management (ISPM) for the kit's own sign-in surface.

Short Answers

What is conditional access in the kit?

A set of rules that allow, step up, or deny a sign-in. Rules use the source country, the network address, threat intelligence lists, and the sign-in policy.

Can I block countries?

Yes. Each country is allowed, conditional (extra verification preferred), or blocked. A defense contractor preset allows the United States and Five Eyes partners, marks close partners as conditional, and blocks a high-risk set.

Does the kit use threat intelligence?

Yes. Feeds from FireHOL, ET Open, and AbuseIPDB lists can deny sign-in from known-bad addresses. Feeds load from a file on air-gapped systems. Entries can be suppressed without deleting them.

What does the threat report show?

Denied and failed sign-ins, unique sources, attack origin by country, the MITRE ATT&CK techniques they map to, top source addresses, and the most-tried usernames. Each count opens the log that produced it.

Is every sign-in logged?

Yes. The logon audit is append-only. It records time, username, outcome, source address, and reason. Passwords and session tokens are never stored.

Conditional Access Controls

ControlWhat It Does
Country access policyAllow, conditional, or deny sign-in by source country, with a world map and pick lists
Network access control listOrdered allow and deny rules by IPv4 or IPv6 range or host name, first match wins
Threat intelligence denyDeny sign-in from addresses on loaded feeds, with fail-open or fail-closed choice
Multifactor authenticationTime-based one-time codes and passkeys (WebAuthn), with RADIUS as a second factor
Password policy and lockoutLength, age, history, complexity, and lockout after failed attempts
Session timeoutsIdle and absolute limits, token rotation, forced logoff
Identity providersLocal accounts, OpenID Connect, Windows Integrated, and Active Directory
SAML 2.0 federationSecurity Assertion Markup Language (SAML) 2.0 identity providers
Classification gateMandatory access control can require a minimum clearance to sign in

Screenshots

The failed sign-ins in the threat report were made for this demonstration against accounts that do not exist.

The Attack / Threat Report counts blocked and failed attempts and maps them to MITRE ATT&CK.
Failed sign-ins are mapped to MITRE ATT&CK technique T1110 Brute Force, with top sources and most-tried usernames.
Every sign-in attempt is logged append-only, with outcome, source, and reason, and exports to CSV or JSON.
Conditional access by country: allow, require extra verification, or deny sign-in by source country.
Ordered network rules allow or deny sign-in by address range before any password check.
Threat intelligence feeds block known-bad addresses at sign-in, and load offline on air-gapped systems.
Sign-in policy covers multifactor authentication, passkeys, password rules, and lockout.
Session timeouts and forced logoff limit the risk of an unattended or stolen session.
Sign in with local accounts, OpenID Connect, Windows Integrated, or Active Directory.

Related Controls

FrameworkControls
NIST SP 800-53AC-2, AC-7, AC-12, AC-17, IA-2, IA-5, SC-7, SC-23, SI-4, AU-2, AU-6
NIST SP 800-1713.1.1, 3.1.8, 3.1.11, 3.1.12, 3.5.3, 3.13.1, 3.14.6
CMMCAC.L2-3.1.8, AC.L2-3.1.12, IA.L2-3.5.3, SC.L1-b.1.x, SI.L2-3.14.6
ISO/IEC 27001Annex A 5.15, 5.17, 8.5, 8.16, 8.20

An assessment organization, certification body, or regulator decides whether a requirement is satisfied.

Identity integrations

Identity systems

  • Microsoft Active Directory
  • Microsoft Entra ID
  • Okta
  • Ping Identity
  • SailPoint
  • Yubico YubiKey
  • RADIUS
  • Lightweight Directory Access Protocol

All logos and trademarks are the property of their respective owners. Their use does not imply endorsement.

See It on Your Use Case

A live demo of privileged access, compliance evidence, and deployment options for your environment.