01Identity Is the New Perimeter
The modern intrusion rarely begins with malware. It begins with a login. As organizations moved workloads to the cloud, adopted SaaS at scale, and federated authentication across dozens of platforms, the identity layer became the most valuable — and most exposed — attack surface in the enterprise. Adversaries no longer need to break in when they can simply sign in with stolen credentials, hijacked tokens, or abused service accounts. Industry telemetry consistently shows most modern detections are malware-free, with compromised identities at the center of successful breaches.
Identity Threat Detection and Response (ITDR) emerged to close this gap. Where Identity and Access Management (IAM) governs who should have access, ITDR continuously watches how identities actually behave — detecting compromise, misuse, and escalation in real time, then driving containment before an attacker converts a single account into full domain control.
02Detecting Credential Abuse, Token Theft, and Privilege Escalation in Real Time
ITDR platforms build a behavioral baseline for every identity — human and non-human — then alert on deviations signaling active attack. Three detection domains matter most.
Domain 01Credential Abuse
The front door: password spraying, credential stuffing, impossible-travel logins, and the successful sign-in that follows a failure storm.
Domain 02Token Theft
Bypasses the password entirely: session cookie replay, AiTM phishing kits, pass-the-hash, and forged Kerberos tickets — often defeating MFA.
Domain 03Privilege Escalation
The pivot: rogue group additions, credentials added to service principals, federation abuse, and dormant admin accounts springing back to life.
Credential abuse is the front door. Password spraying, credential stuffing, and brute-force campaigns generate telltale authentication patterns: high failure volumes across many accounts, logins from anonymizing infrastructure, and “impossible travel” between geographically distant sessions. Real-time ITDR correlates these signals across on-premises Active Directory and cloud identity providers, flagging the successful login that follows a failure storm — the moment an attacker transitions from guessing to using.
Token theft bypasses the password entirely. Adversaries steal session cookies, OAuth access tokens, and Kerberos tickets to impersonate authenticated users, often defeating multi-factor authentication in the process. Adversary-in-the-middle phishing kits capture session material at scale, while techniques such as pass-the-hash and Kerberos ticket forgery abuse authentication artifacts inside the network. ITDR detects the downstream anomalies: a token replayed from a new device fingerprint, a session that suddenly changes geography or user-agent, or a Ticket Granting Ticket with an anomalous lifetime.
Privilege escalation is the pivot. Once inside, attackers manipulate group memberships, add credentials to service principals, create rogue federation trusts, or exploit misconfigured delegation to climb from user to administrator. ITDR watches the identity control plane itself — directory changes, role assignments, and permission grants — and raises high-fidelity alerts when a standard account suddenly acquires privileged rights or when dormant admin credentials spring back to life.
03Where ITDR Fits Alongside EDR, SIEM, and Your IAM Stack
ITDR does not replace existing controls; it completes them. Think of the detection stack as three lenses aimed at different layers of the same attack.
EDR watches the endpoint. It excels at detecting malicious processes, persistence mechanisms, and lateral movement tooling — but an attacker using valid credentials through legitimate protocols generates little for EDR to see. ITDR covers exactly that blind spot, detecting identity misuse that never touches a monitored host.
SIEM aggregates and correlates. It remains the SOC’s analytic backbone, but its identity coverage is only as good as the detections feeding it. ITDR acts as a specialized sensor, streaming enriched, identity-centric alerts into the SIEM where they can be correlated with endpoint, network, and cloud telemetry for full attack-chain visibility.
IAM, PAM, and IGA define the preventive layer — provisioning access, enforcing MFA, vaulting privileged credentials, and certifying entitlements. ITDR is their detective counterpart: it verifies that the access model is behaving as designed, exposes gaps such as shadow admins and stale accounts, and triggers response actions — session revocation, forced re-authentication, account disablement — through the same IAM machinery. Together they form a closed loop: IAM sets the policy, ITDR validates reality, and response actions restore the intended state.
04Practical Detection Use Cases Mapped to MITRE ATT&CK
Mapping ITDR detections to MITRE ATT&CK gives teams a common language for coverage measurement and gap analysis. These use cases are high-value starting points.
| Use Case | ATT&CK Technique | Detection Signal | Response Action |
|---|---|---|---|
| Password spraying campaign | T1110.003 — Brute Force: Password Spraying | Authentication failures across many accounts from shared source infrastructure | Block source, enforce step-up MFA, reset targeted accounts |
| Session cookie theft | T1539 — Steal Web Session Cookie | Token replay from new device fingerprint or impossible-travel geography | Revoke sessions and refresh tokens, force re-authentication |
| Kerberoasting | T1558.003 — Steal or Forge Kerberos Tickets: Kerberoasting | Spike in RC4 service-ticket requests from a single principal | Rotate service account passwords, alert on offline cracking indicators |
| Pass-the-hash lateral movement | T1550.002 — Use Alternate Authentication Material | NTLM authentication anomalies inconsistent with user baseline | Isolate host via EDR, disable account, hunt for source of hash |
| MFA fatigue attack | T1621 — Multi-Factor Authentication Request Generation | Burst of push notifications followed by an approval | Suspend account, invalidate sessions, verify user out-of-band |
| Rogue privilege grant | T1098 — Account Manipulation | Standard identity added to privileged group outside change control | Auto-revert membership, open incident, review grantor account |
05The Bottom Line
Attackers have industrialized identity compromise; defenders must industrialize identity detection. ITDR delivers the real-time behavioral lens that EDR, SIEM, and IAM each lack on their own — turning the identity layer from your largest blind spot into your highest-fidelity source of early warning. Start with the ATT&CK-mapped use cases above, wire responses into your existing IAM controls, and measure coverage continuously. In an era where the perimeter is a login prompt, watching identity is not optional — it is the program.
Key Takeaway
IAM sets the policy. ITDR validates reality. Response actions restore the intended state. Close the loop, and the identity layer becomes your earliest warning system instead of your largest blind spot.