If somebody steals your credentials and abuses them no network device has any way of knowing that.
The closest any Cisco product come would be something like Stealthwatch. By analyzing Netflow records it will alert you to things like logins coming from unusual places or unusual flows out of your network (e.g. data exfiltration).
You could help that somewhat with Firepower by blocking, for instance, connections from some geographic regions based on the IP addresses. It doesn't completely address the root problem you're asking about but is a countermeasure of sorts.