Identity threats and ITDR, by ear
15 episodes, in order, 3 checked against transcripts. How attackers abuse identity, and how teams detect and respond. Start at the top if the topic is new to you, or jump to the stage that matches where you are.
Start here: the basics
- 1The Real-World State of ITDR with Brian DesmondHybrid Identity Protection Podcast · 2022-09-08 · 29 min · Learner
Introduces identity threat detection and response from the view of hands-on identity teams and where organizations struggle most.
Brian Desmond (Ravenswood Technology Group)itdr - 2Analyst Chat #212: Securing the Front Door: The Importance of ITDR in Identity ProtectionKuppingerCole Analyst Chat · 2024-04-29 · 19 min · Learner
Explains why attackers now target identity systems as an entry point, what ITDR tools do, and why identity and security operations teams must cooperate.
Checked against the transcriptMike Neuenschwander (KuppingerCole Analysts)itdr - 3ITDR Deep Dive with Matt Caufield - Exploring the Next Big Thing in Identity & Access ManagementThe Identity Jedi Show · 2023-05-18 · 31 min · Learner
Discusses ITDR as an emerging category and how it differs from traditional identity and access management controls.
Matt Caulfielditdr
In practice: rollouts and operations
- 4EP 16 - Beware of Stolen Cookies for MFA BypassSecurity Matters (formerly Trust Issues) · 2022-12-06 · 35 min · Practitioner
Explains session cookie hijacking, how stolen cookies let attackers skip MFA, and why the technique grew through 2022.
- 5EP 39 - Analyzing the MGM and Okta Breaches: the Identity ConnectionSecurity Matters (formerly Trust Issues) · 2023-11-02 · 33 min · Practitioner
Breaks down the 2023 MGM help desk social engineering attack and the Okta support system breach, and the identity weaknesses both exploited.
Andy Thompson (CyberArk Labs)okta 2023 support system breach - 6EP 46 - Behind the Data Breach: Dissecting Cozy Bear's Microsoft AttackSecurity Matters (formerly Trust Issues) · 2024-02-15 · 32 min · Practitioner
Dissects the Midnight Blizzard (APT29) breach of Microsoft, including password spraying a legacy test tenant and abusing OAuth applications for access.
Andy Thompson (CyberArk Labs)midnight blizzard 2024 microsoft - 7EP 49 - Inside the Attack Surface: Lessons from the Red Team on Browser ThreatsSecurity Matters (formerly Trust Issues) · 2024-04-03 · 30 min · Practitioner
Explains why attackers moved from stealing passwords to hijacking session tokens and cookies, and why the browser is now a main identity attack surface.
Shay Nahari (CyberArk)infostealer session hijacking - 8Risky Business #751 -- Snowflake, operation Endgame and Microsoft's looming FTC problemRisky Business · 2024-06-05 · 64 min · Practitioner
News discussion of the 2024 Snowflake customer breaches, where stolen credentials against accounts without mandatory MFA led to mass data theft.
- 9#409 - Q1 2026 Identity Threat Report RoundupIdentity at the Center · 2026-03-23 · 59 min · Practitioner
Summarizes seven Q1 2026 threat reports and the identity patterns they share, including MFA gaps, machine identity abuse, deepfakes, and faster breach timelines.
- 10Microsoft DART: In the Trenches with Shiva PHybrid Identity Protection Podcast · 2024-11-22 · 39 min · Practitioner
A Microsoft incident responder walks the attack kill chain from initial access to ransomware extortion and shares ways to reduce identity risk.
Shiva P (Microsoft DART)itdr
Going deeper: standards, architecture, and attacks
- 11How a Single Breach Can Turn into a Full Compromise with Tim Beasley, Senior Incident Response Consultant at SemperisHybrid Identity Protection Podcast · 2026-02-17 · 40 min · Architect
Explains how attackers escalate through identity infrastructure after initial access, and why identity defense needs a recovery-first plan as well as prevention.
Tim Beasley (Semperis)itdr - 12Tracking Tier 0 Attack Paths with Ran HarelHybrid Identity Protection Podcast · 2023-03-01 · 27 min · Architect
What Tier 0 assets are, how attack paths through Active Directory lead to them, and how to manage those paths in hybrid AD environments.
Includes a promotion of the publisher's own product.
Checked against the transcriptRan Harel (Semperis)techniques - 13Red Team Secrets: How we bypass Conditional Access (and how you can fix it)Entra.Chat · 2025-08-29 · 58 min · Architect
A red teamer shows how attackers bypass Entra Conditional Access through FOCI client families and token endpoint gaps, and how to harden policies.
Fabian Bader (glueckkanja)conditional access policies guide - 14Hacking Entra ID: Bypassing AppLocks & Creating ‘Immortal’ UsersEntra.Chat · 2025-11-08 · 52 min · Architect
Covers Entra ID attack research: backdooring service principals, restricted administrative units that create undeletable accounts, AppLock bypass, and Copilot Studio OAuth phishing.
Katie Knowles (Datadog)itdr - 15Analyst Chat #267: ITDR & Machine Identities (NHIs) - Rethinking IAM for Security at ScaleKuppingerCole Analyst Chat · 2025-09-01 · 66 min · Architect
Separates real ITDR capability from vendor relabeling, contrasts visibility with observability of identity behavior, and argues hygiene must come before detection.
Checked against the transcript
How this list was built
Episodes are chosen for what they teach, not for who published them, and ordered so each one builds on the last. Each note is checked against the episode's published transcript where one exists (marked under the episode) and against its show notes otherwise. Vendor-produced shows are labelled on their directory profiles. Know a better episode for a step on this path? Email [email protected].