Back to Field Notes
Identity & Access/Field Note

ITDR — Identity Threat Detection and Response, Honestly

ITDR catches token theft, anomalous federation, OAuth abuse, and IdP attacks that EDR cannot see. It is not optional.

Author

Aisha Khan

Director, Threat Intelligence

Published

March 18, 2026

Read

9 min

Share
AI-generated illustration of a banking facility
AI-generated illustration of a banking facility
Key Takeaways
  • 01ITDR addresses a real gap: identity-layer attacks that EDR and SIEM individually do not catch well. Increasingly a requirement, not a nice-to-have.
  • 02What ITDR detects well: token theft and replay (cookie theft, refresh token abuse), OAuth consent attacks against your tenant, anomalous federation events (Golden SAML, malicious app registrations), privilege escalation chains in cloud identity (especially Entra ID), service-account behavior anomalies (off-hours, off-region, off-pattern).
  • 03Overlap with adjacent tools: SIEM ingests IdP logs but lacks identity-aware analytics out of the box, EDR sees endpoint-side token theft but not server-side replay, CSPM sees identity misconfigurations but not active attacks. ITDR's value is the intersection — purpose-built analytics joining those signals.
  • 04Buying criteria: coverage of your IdP and cloud IAMs (not just Entra ID), native ingestion of your EDR signal, out-of-the-box content for the attacks you care about, open API for content authoring, integration with your SOAR for response.

Identity Threat Detection and Response (ITDR) is a relatively new product category that addresses a real gap: identity-layer attacks that EDR and SIEM individually do not catch well. It is increasingly a requirement, not a nice-to-have.

What ITDR detects well

  • 01Token theft and replay (cookie theft, refresh token abuse)
  • 02OAuth consent attacks against your tenant
  • 03Anomalous federation events (Golden SAML, malicious app registrations)
  • 04Privilege escalation chains in cloud identity (especially Azure AD)
  • 05Service account behavior anomalies (off-hours, off-region, off-pattern)

Where ITDR overlaps with adjacent tools

There is overlap with SIEM (which can ingest IdP logs but lacks identity-aware analytics out of the box), with EDR (which sees endpoint-side token theft but not server-side replay), and with CSPM (which sees identity misconfigurations but not active attacks). ITDR's value is at the intersection — purpose-built analytics that join those signals.

Buying criteria

Coverage of your IdP and cloud IAMs (not just Azure AD). Native ingestion of your EDR signal. Out-of-the-box content for the attacks you care about. Open API for content authoring. Integration with your SOAR for response.

#ITDR#Detection#Identity

/WRITTEN_BY

Aisha Khan

Director, Threat Intelligence · Alexa Cybersecurity