Sense
Sign inBook a demo
Account Takeover · login and post-login session risk

The credentials were right. The person wasn't.

Sense scores the whole session — device fingerprinting, behaviour, network and remote-access activity — from login to payment confirmation, so stolen passwords and screen-sharing scams are caught by behaviour, not by security questions.

Book a demo
2.4%of logins scored high-risk last month
30 msadded on the risk call, p99
61%fewer OTPs sent to known devices
SESSION · netbanking.yourbank.in4,120 logins/min
09386794
SESSION RISKre-scored on
every action
Login · correct passwordfirst sight of this browser · 340km from home
WATCH
OTP entered in 4 secondspaste event, no keystrokes, clipboard source
STEP UP
Remote access session activescreen-share tool in foreground · overlay drawn
FREEZE
New payee added · ₹1,84,000added and paid inside 90 seconds
BLOCK
Returning customer · same browser 14 monthstyping cadence and navigation match the profile
ALLOW
SESSIONS AT RISK2.4%
TO YOUR STACK
Intervene before the money moves, not afterrisk + reason codes on the auth and payment call · 30ms p99
No extra OTP
01 Login02 Session03 Attacks04 Policy05 Deploy
Login is one moment. The session is the whole story
HOW IT WORKS

Four signal families, scored continuously.

Every credential in circulation should be assumed known, and every OTP assumed reachable. What an attacker cannot copy is the session history, the hand on the keyboard and the absence of someone else's software in the browser.

01Browser & networkBrowser history with this account, automation and headless artefacts, VPN and residential proxy pools, ASN reputation, impossible travel.
02Behavioural biometricsTyping cadence, pointer travel, scroll physics, form dwell, navigation habit — compared against this customer's own baseline, not a population average.
03Credential & identity intelBreach and combolist exposure, reset and MFA-change velocity, contact-detail edits, one identity appearing across unrelated sessions.
04Session integrityRemote access and screen-share tools, accessibility-service abuse, overlays, injected scripts and hijacked or replayed session tokens.
LOGIN RISK · ONE CALLre-scored live
BROWSERUnseen browser profileFresh session, no historyRemote-control extensionHeadless artefacts
BEHAVIOUROTP pasted, not typedCadence off baselineImpossible travelCredential in combolist
Browser never seen on this identity+34
Session opened through a proxy pool+26
One-time code pasted from clipboard+21
Password reset attempted first+13
01 · LOGIN

A password proves nothing. A history proves a lot.

Sense answers the only question at the login screen: is this the browser, hand and network this account has always used? Risk arrives with the auth call, before a session exists.

Silent for the customer you know
A returning browser with a matching behavioural profile passes straight through — no OTP, no security question, no friction on the happy path.
Friction only where it earns its keep
Step-up is reserved for genuinely risky sessions, so your OTP spend and your drop-off both fall.
Works with the auth you already run
Sense scores alongside your IdP or in-house login — no migration, no change to how credentials are stored.
Reason codes on every verdict
The signals that drove the score come back with it, so your fraud team can defend an intervention to a customer or a regulator.
02 · SESSION

Most takeovers begin after a clean login.

A victim on a scam call logs in themselves — legitimate at the door, hostile ten minutes later. Sense keeps scoring every action, and freezes the transfer, not the customer.

Risk attached to the action, not the login
The payment call carries its own score, so a session that turned bad after authentication is still stopped.
Remote access and screen share, detected in place
Screen-share tools, remote-control extensions and overlays are visible in the page while they are happening.
The page the customer sees, checked against the page you shipped
Injected fields, rewritten beneficiary details and fake step-up prompts are reported as a DOM diff travelling with the payment call.
Trusted-session continuity
A recognised browser survives cache clears and network changes, so genuine customers are not re-challenged for switching WiFi.
SESSION TIMELINE · ONE CUSTOMERlive
00:00 · login, correct password, new browserscore 38WATCH
00:41 · screen-share tool enters foregroundscore 71STEP UP
01:06 · beneficiary field rewritten in the pagescore 83HOLD
01:48 · new payee added, IFSC never seenscore 91FREEZE
02:02 · ₹1,84,000 transfer submittedscore 94BLOCK
// what your payment service sees
x-sense-session-risk: 94
x-sense-reasons: remote_access_active, dom_tampered, new_payee_velocity
x-sense-action: block_and_notify
Sessions scored this month318M
03 · ATTACKS

Five ways an account changes hands.

Takeover is rarely one exploit — it is a chain: exposed credentials, an intercepted code, a helpful voice on the phone, then a payee that was never yours. Each link leaves a signal.

PATTERNHOW IT REACHES THE ACCOUNTWHAT SENSE DOESOUTCOME
Credential stuffing and phishing kits
HOW IT REACHES THE ACCOUNTReused passwords from a breach, or a live phishing page relaying the real login and code in real time.
WHAT SENSE DOESScores browser novelty, behavioural mismatch and relay latency at the auth call, and steps the session up before it is established.
OUTCOMEA known password stops being enough.
Man-in-the-browser edits
HOW IT REACHES THE ACCOUNTA trojan or a malicious extension rewrites the page in front of the customer — new fields, a changed beneficiary, a convincing fake step-up prompt.
WHAT SENSE DOESCompares the live page to the one you shipped, and names the extension listeners attached to password and OTP inputs.
OUTCOMEThe customer sees your page, or you know they didn't.
Real-time OTP relay
HOW IT REACHES THE ACCOUNTA phishing page collects the code and replays it into your real login within seconds, from the attacker's browser.
WHAT SENSE DOESCorrelates an unseen browser, a pasted code and relay latency, and holds the session for out-of-band verification.
OUTCOMEThe code alone cannot carry the login.
Remote access and screen-share scams
HOW IT REACHES THE ACCOUNTThe customer logs in themselves while a caller watches the screen and dictates the transfer.
WHAT SENSE DOESDetects screen-share tools, remote-control extensions and overlays in the page and freezes the money action mid-session.
OUTCOMEAuthorised-but-unintended payments stop.
Session and token hijack
HOW IT REACHES THE ACCOUNTA stolen cookie or token replayed from a different browser, network and time zone, skipping login entirely.
WHAT SENSE DOESBinds the session to its browser and behavioural fingerprint, so a replayed token fails the continuity check.
OUTCOMEStolen sessions die on first use.
Reset and profile-change abuse
HOW IT REACHES THE ACCOUNTPassword, email or phone changed first, then limits raised and a new payee added minutes later.
WHAT SENSE DOESTreats the change chain as one risk event and requires re-verification before the payment path reopens.
OUTCOMEQuiet account grooming is surfaced.
FOR FRAUDSession risk lands on the same event bus as your bot and transaction signals, so one rule can reason across all three.
FOR CUSTOMER SUPPORTEvery hold arrives with plain reasons, so an agent can tell a caller why the transfer stopped.
FOR GROWTHStep-up only where risk earns it: fewer OTPs sent, fewer abandoned logins, lower auth cost per user.
FOR COMPLIANCEDecisions, scores and reason codes are retained and exportable for RBI, NPCI and internal audit review.
04 · POLICY

Decide what each risky moment deserves.

Allow, step up or block — per trigger, changed from the dashboard without a release. Set it below the way your risk team would.

RISK TRIGGERALLOW · STEP UP · BLOCK
Login from an unseen browser
Impossible travel or proxy relay
Remote access tool active in session
Password or MFA reset, then payment
New payee plus high-value transfer
Page tampered mid-session
Returning browser, matching behaviour
Posture:Recommended3 of 7 triggers block outright, the rest are step up or allowed through.
Step-up you already ownRoute a risky session into your existing passkey, biometric or Silent Mobile Verification check — Sense decides when, not what.
Shadow mode firstRun a fortnight of scoring with no enforcement, reconcile against your own confirmed-fraud cases, then switch actions on.
Auditable interventionsEvery hold and block is stored with its score, reason codes and the policy version that applied.
05 · DEPLOY

Scoring your logins this week, enforcing when you say so.

01
Instrument login and the money paths
The mobile SDK or a JS tag on web, plus a server-side call on auth, payee change and transfer. No auth migration.
02
Baseline in shadow mode
Scores flow without enforcement while you compare verdicts against your own confirmed takeover and disputed-transaction cases.
03
Turn on step-up, then holds
Start with step-up on new-browser logins, then add holds on high-risk payee and transfer events as confidence builds.
SITS ON WHAT YOU ALREADY RUN
OktaAuth0Ping IdentityKeycloakAWS CognitoWeb JS tagServer-side API

Nothing about how you store or verify credentials changes. Sense observes the session and returns a risk verdict on the calls you already make — at auth, at profile change and at payment.

FOOTPRINT
30 msp99 on the risk call
0changes to your auth flow

See the takeovers you are currently paying for.

Two weeks of shadow-mode session scoring on your real logins, reconciled against your own fraud cases.