Identity Threat Detection and Response (ITDR)
Identity Threat Detection and Response (ITDR) is the set of methods and tools used to detect, investigate and defend against attacks on identities, accounts and permissions. These include compromised credentials, privilege escalation, misused service accounts and manipulation of identity services such as directory or single sign-on systems.
ITDR differs from identity and access management (IAM): while IAM manages identities and controls access preventively, ITDR concentrates on the ongoing detection of misuse of already granted or stolen permissions. Typical signals are unusual login patterns, unexpected permission changes, lateral movement across accounts or access from atypical contexts. Detected identity threats are followed by responses such as locking accounts, resetting credentials or revoking sessions and tokens.
ITDR is thus a building block of Identity Security and supports Zero Trust strategies in which identities are regarded as the central control point. Since many modern attacks work not with malware but with valid credentials, ITDR closes a gap between endpoint, network and identity protection.