Supported protocols and evidence

Generic protocol rules plus selected vendor-aware patterns. Vendor coverage can expand without changing the core evidence model.

SAML 2.0

Audience, ACS/Destination/Recipient, Issuer, status, NameID, validity, request correlation, signing errors and attributes.

OAuth 2.0 / OIDC

Redirect URI, client credentials, state, nonce, PKCE, token exchange, issuer/audience and signing/JWKS errors.

RADIUS

Access-Request, Challenge, Accept/Reject, MFA continuation, NPS/FreeRADIUS patterns and post-auth VPN/NAS handling.

LDAP / Active Directory

User lookup, bind/credentials, locked/disabled accounts, password expiry and repository selection.

Kerberos

Pre-authentication, unknown principals/SPNs, account revocation, clock skew, encryption and ticket validation.

FIDO2 / WebAuthn

RP ID, browser origin, challenge/session correlation, user verification and authenticator-state anomalies.

Analyze a caseBack home