MFA fatigue: what the SOC actually sees before the click
In my evaluations, the teams that catch MFA fatigue early aren't watching the push flood. They've already seen the infostealer hit, the credential-validation spike, the login from an unfamiliar IP days before the first prompt. The flood is the last stage worth catching, not the first.