Start with Identity
← Glossary
Concept

ITDR

Identity Threat Detection and Response. Security tooling that detects and responds to identity-based attacks such as account takeover, privilege escalation, and lateral movement, often across Active Directory, Entra ID, and cloud IdPs. Complements prevention and posture by catching attacks at runtime.

ITDR exists because endpoint and network tools do not see identity attacks: there is no malware in a valid login with a stolen token. It watches the identity control plane itself, which in most enterprises means Active Directory and the cloud IdP together, since attackers routinely pivot between them. The detections that matter are behavioral, because every individual action in the chain is technically authorized.

See also: what is ITDR, lateral movement, ISPM, ITDR vendors

Last reviewed By SWI Community TeamSuggest a correctionHow we research