Detectory
Blog

Field guides for enrollment fraud detection

Analysis for teams detecting fake documents, synthetic identities, outstanding-verification abuse, and broker-driven enrollment fraud.

Technical GuideProgram IntegrityComplianceStrategySecurityArchitecture
Program Integrity15 min read

5 Best Public Benefits Fraud Detection Platforms in 2026

Compare fraud detection platforms for health marketplaces and public-benefit programs by document forensics, identity proofing, network analytics, case evidence, and applicant friction.

Compliance11 min read

MARS-E and NIST 800-63 for Fraud Platforms: A State Exchange Roadmap

A plain-language guide to sequencing SOC 2, MARS-E, NIST 800-63 IAL2, StateRAMP, and FedRAMP so a fraud-detection vendor can sell to state marketplaces.

Strategy11 min read

The $186B Problem: A Program-Integrity Playbook for Improper Payments

Turn the GAO Fraud Risk Framework into an operational playbook: where to instrument detection, how to triage cases, and how to measure catch rate without raising premiums.

Security12 min read

Synthetic Identity in Public Benefits: Catching SSN Reuse Before Coverage

How to spot synthetic and duplicate-identity patterns in benefit enrollment, from one SSN across many policies to issuance-date anomalies, and stop them at the front door.

Technical Guide12 min read

Document Forensics at Scale: Catching Fake Paystubs and SEP Letters

Template-deviation, font-substitution, metadata, and OCR-consistency signals expose fabricated income and coverage-loss documents that overloaded human reviewers miss.

Strategy11 min read

Referral-Grade Evidence: Audit Trails That Survive CMS and an MFCU

The Pondera failure wrongly suspended 600K+ claimants. Here is what a defensible, human-in-the-loop referral packet contains and how confidence scoring prevents wrongful terminations.

Technical Guide20 min read

Broker Rings, Not Bad Forms: Detecting Organized Enrollment Fraud

Single-application document checks miss the fraud pattern. Graph analytics across applications reveal the broker clusters, shared SSNs, and coordinated SEP velocity that define organized fraud.

Program Integrity17 min read

Why 23 of 24 Fake Applications Were Approved and How to Close the Front Door

The GAO slipped 24 fraudulent applications past marketplace controls. We break down each fraud vector and map the front-door detection architecture that stops them.

Security18 min read

Cross-Account Identity Attacks: How Lateral Movement Exploits AWS Trust Policies

Attackers exploit cross-account role assumptions and confused deputy vulnerabilities to move laterally across AWS environments. Identity-level detection catches these attacks before network tools see them.

Strategy16 min read

The ITDR Buyer's Checklist: What to Evaluate Before You Sign

A practitioner's framework for evaluating identity threat platforms. Coverage depth, detection methodology, automation maturity, and the 12 questions vendors hate answering.

Technical Guide15 min read

CloudTrail Is Not Enough: What Your Identity Detection Stack Is Missing

CloudTrail logs events, but without behavioral baselines, identity resolution, and NHI lifecycle tracking, you're blind to the threats that matter. Here's what a complete stack looks like.

Architecture12 min read

Progressive Response Automation: A Practical Maturity Model for Security Teams

Move security playbooks from alerts to controlled automation with clear ownership, observable decisions, reversible actions, and promotion criteria defined by your own environment.

Technical Guide20 min read

Securing AI Agents in Production: Identity Guardrails for Autonomous Systems

AI agents with AWS permissions operate beyond human oversight. Learn how to monitor autonomous identity behavior, detect prompt-injection attacks, and build kill switches before agents escalate privileges.

Security21 min read

The Service Account Time Bomb: Auditing AWS Non-Human Identity Sprawl

97% of non-human identities have excessive privileges. We audited 200+ AWS accounts to quantify the NHI sprawl crisis and built a practical remediation framework.

Architecture17 min read

Building a Zero-Trust Detection Pipeline with Identity-First Monitoring

Map the architecture of an identity-centric detection pipeline: CloudTrail ingestion, behavioral baselining, anomaly scoring, and progressive response. Zero-trust principles apply to detection too - verify every identity action, assume breach.

Strategy14 min read

SIEM vs AI-Native Detection: Why Log Queries Can't Stop Identity Attacks

SIEMs take 28 days to detect compromised credentials. Purpose-built ITDR platforms catch them in 4 hours. Here's why traditional log aggregation fails for modern identity threats.

Technical Guide19 min read

AI Anomaly Detection: How Pattern Recognition Prevents Identity Breaches

Behavioral baselines catch compromised credentials 3-5 days faster than static rules. Learn how CloudTrail event patterns reveal role assumption attacks, impossible travel, and API abuse.

Strategy9 min read

Why Identity Is the New Security Perimeter

The traditional network perimeter is gone. With cloud-native architectures, remote workforces, and AI agents, identity has become the true boundary that separates trusted access from threat.

Technical Guide10 min read

How to Monitor AI Agents in Your AWS Environment

AI agents are making API calls across your AWS accounts right now. Most security teams have no visibility into what these agents do, which roles they assume, or whether their behavior is normal.

Security9 min read

The Non-Human Identity Problem: Why Service Accounts Are Your Biggest Blind Spot

Non-human identities outnumber human users 10-to-1 in most organizations. Yet the majority of security tooling focuses on human access reviews and permission policies, not runtime behavior.

Architecture10 min read

Progressive Trust: A Better Model for Cloud Security Automation

Security automation does not have to be all-or-nothing. Progressive trust introduces five levels of autonomy, letting teams build confidence in automated responses over time.