ITDR — IDENTITY THREAT DETECTION & RESPONSE

Identity is the new
attack surface.

80% of breaches involve compromised credentials. DKTrace ITDR monitors every authentication, every privilege use, and every lateral move — detecting identity-based attacks in seconds, not days.

100%
AD / Entra ID coverage
12 sec
Mean detection latency
300+
Identity attack patterns
0
Cloud dependency

Identity Attack Detection

Detect password spraying, credential stuffing, brute force, kerberoasting, pass-the-hash, and golden/silver ticket attacks across AD and cloud IAM.

Compromised Account Triage

When an account shows compromise signals, DKTrace ITDR correlates identity logs, endpoint telemetry, and network activity into a single case with blast radius mapping.

Privileged Access Monitoring

All privileged account activity — admin logins, sudo commands, role assignments, policy changes — monitored in real time with automatic anomaly escalation.

Lateral Movement Detection

Graph-based analysis of authentication chains. Detect pass-the-ticket, over-pass-the-hash, and token manipulation as they move between systems.

Federated Identity Coverage

Native support for Active Directory, Azure AD / Entra ID, Okta, Ping Identity, CyberArk, and SAML / OIDC federations. One unified identity timeline.

Automated Response Actions

Force password reset, disable account, revoke tokens, terminate sessions, and notify ITSM — all triggered automatically by configurable risk thresholds.

TA0006 — Credential Access
Kerberoasting (T1558.003)
LSASS dumping (T1003.001)
Credential stuffing (T1110.004)
TA0008 — Lateral Movement
Pass the Hash (T1550.002)
Pass the Ticket (T1550.003)
Remote services abuse (T1021)
TA0004 — Privilege Escalation
Token impersonation (T1134)
Sudo / su abuse (T1548.003)
Group policy modification (T1484)
TA0003 — Persistence
Golden Ticket (T1558.001)
Account manipulation (T1098)
Shadow credentials (T1556.006)
Microsoft Active DirectoryAzure AD / Entra IDOktaPing IdentityCyberArk PAMSailPointBeyondTrustHashiCorp VaultAWS IAMGoogle WorkspaceRADIUSLDAP / LDAPS

Stop attackers the moment they touch your identity layer.

Live ITDR demo — we'll simulate a pass-the-ticket attack on your AD profile.

Book an ITDR Demo