Supported protocols and evidence
Generic protocol rules plus selected vendor-aware patterns. Vendor coverage can expand without changing the core evidence model.
SAML 2.0
Audience, ACS/Destination/Recipient, Issuer, status, NameID, validity, request correlation, signing errors and attributes.
OAuth 2.0 / OIDC
Redirect URI, client credentials, state, nonce, PKCE, token exchange, issuer/audience and signing/JWKS errors.
RADIUS
Access-Request, Challenge, Accept/Reject, MFA continuation, NPS/FreeRADIUS patterns and post-auth VPN/NAS handling.
LDAP / Active Directory
User lookup, bind/credentials, locked/disabled accounts, password expiry and repository selection.
Kerberos
Pre-authentication, unknown principals/SPNs, account revocation, clock skew, encryption and ticket validation.
FIDO2 / WebAuthn
RP ID, browser origin, challenge/session correlation, user verification and authenticator-state anomalies.
