Best Identity Threat Detection and Response (ITDR) Software - Page 3

How Many Identity Threat Detection and Response (ITDR) Software Products Does G2 Track?

Total Products under this Category: 73

Category Stats (Oct 2026)

  • Average Rating: 4.57/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Falcon Identity protection (+2.92%) - Among all products in this category, Falcon Identity protection recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Identity Threat Detection and Response (ITDR) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,900+ Authentic Reviews
  • 73+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Identity Threat Detection and Response (ITDR) Software

G2 Grid® for Identity Threat Detection and Response (ITDR)  Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Huntress Managed ITDR, Abnormal AI, Okta, Microsoft Defender for Identity, Guardz, IBM MaaS360, and Idira Identity Security Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/identity-threat-detection-and-response-itdr/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=huntress-managed-itdr&focus%5B%5D=abnormal-ai&focus%5B%5D=okta&focus%5B%5D=microsoft-defender-for-identity&focus%5B%5D=guardz&focus%5B%5D=ibm-maas360&focus%5B%5D=idira-identity-security-platform)

Push Security

Push Security is on a mission to defend organizations where work and attacks actually happen: in the browser. Built by red and blue team experts, Push gives defenders visibility, control, and response power in a layer that’s historically been overlooked, but increasingly targeted. Push is the most advanced security tool in the browser. It brings real-time detection and response to the layer where users work — and where attackers operate. By deploying a powerful agent inside the browser, Push gives defenders full visibility into user activity, attacker behavior, and browser-level risk. It detects threats like phishing kits and session hijacking, enforces protective controls like MFA and SSO, and provides the telemetry security teams need to investigate fast. Push works in any modern browser, deploys in minutes, and integrates easily with the rest of your stack — making it accessible to teams of any size.

Average Rating: 4.8/5.0

Total Reviews: 9

How Do G2 Users Rate Push Security?

  • Quality of Support: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 9.4/10 (Category avg: 9.0/10)

Who Is the Company Behind Push Security?

  • Seller: Push Security
  • Year Founded: 2021
  • HQ Location: Boston, MA
  • Twitter: @PushSecurity
    715 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    99 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 56% Medium, 22% Large

What Are Recent G2 Reviews of Push Security?

SentinelOne Singularity Identity Detection & Response

Singularity Identity is an identity threat detection and response (ITDR) solution that protects on-premises and cloud-hosted Active Directory domain controllers and domain-joined endpoints in real time. A component of the Singularity Platform, Singularity Identity detects active attacks against all device types and OSes, and safeguards against unauthorized privilege escalation and lateral movement.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate SentinelOne Singularity Identity Detection & Response?

  • Quality of Support: 5.8/10 (Category avg: 9.1/10)
  • Ease of Use: 9.2/10 (Category avg: 9.0/10)

Who Is the Company Behind SentinelOne Singularity Identity Detection & Response?

  • Seller: SentinelOne
  • Year Founded: 2013
  • HQ Location: Mountain View, CA
  • Twitter: @SentinelOne
    57,863 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,529 employees on LinkedIn®
  • Ownership: NASDAQ: S

Who Uses This Product?

  • Company Size: 50% Medium, 50% Small

What Are Recent G2 Reviews of SentinelOne Singularity Identity Detection & Response?

Silverfort

Silverfort’s Unified Identity Protection Platform is the first to consolidate security controls across corporate networks and cloud environments to block identity-based attacks. Using innovative agentless and proxyless technology, Silverfort seamlessly integrates with all existing IAM solutions (e.g., AD, RADIUS, Azure AD, Okta, Ping, AWS IAM), extending coverage to assets that could not previously have been protected, such as legacy applications, IT infrastructure, file systems, command-line tools, and machine-to-machine access. Our platform continuously monitors all access of users and service accounts across both cloud and on-premise environments, analyzes risk in real time, and enforces adaptive authentication and access policies.

Average Rating: 4.8/5.0

Total Reviews: 18

How Do G2 Users Rate Silverfort?

  • Quality of Support: 9.9/10 (Category avg: 9.1/10)
  • Ease of Use: 9.9/10 (Category avg: 9.0/10)

Who Is the Company Behind Silverfort?

  • Seller: Silverfort
  • Year Founded: 2016
  • HQ Location: Tel Aviv, Israel
  • Twitter: @silverfort
    657 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    637 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 44% Small, 39% Medium

What Do G2 Reviewers Say About Silverfort?

AI-generated summary from verified user reviews

Pros
  • Users value Silverfort's strong security capabilities with easy MFA enforcement across various services, enhancing internal protection.
  • Users find Silverfort's ease of use impressive, enabling intuitive policy creation and seamless implementation of security features.
  • Users value the comprehensive MFA protection that Silverfort provides for their entire internal environment seamlessly.
  • Users appreciate the setup ease of Silverfort, enabling effective MFA implementation without extensive installation across devices.
  • Users appreciate the time-saving capabilities of Silverfort, streamlining policy creation and MFA implementation across their systems.
Cons
  • Users report poor customer support when resolving issues, leading to frustration and delays in updates and resolutions.
  • Users find the upgrade process cumbersome, requiring approval from support before proceeding with updates.
  • Users find the complexity of navigating Silverfort's interface hampers effective threat investigation and workflow efficiency.
  • Users struggle with difficulties locating relevant information in Silverfort, finding navigation and filtering less efficient than expected.
  • Users report implementation difficulties with Silverfort due to inefficient workflows and bugs during setup.

What Are Recent G2 Reviews of Silverfort?

What Are G2 Users Discussing About Silverfort?

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

Tracebit Community Edition

Tracebit Community Edition makes canary credentials available to everyone, free forever. Deploy decoy credentials on your devices and in your development workflows. When attackers use them, Tracebit alerts you with the context you need to investigate. Canary types include AWS credentials, SSH keys, browser session cookies, website passwords, and emails. Deploy your first canary in under 60 seconds using the Tracebit Community CLI or issue canaries programmatically through the Tracebit API. A GitHub Action also lets you place canary credentials in CI/CD workflows to detect supply-chain attacks. The Community CLI supports Windows, macOS, and Linux and keeps deployed credentials up to date. View and monitor your canaries in the Community Edition dashboard and receive email alerts when they are triggered. Get started at https://community.tracebit.com/join.

Average Rating: 5.0/5.0

Total Reviews: 2

How Do G2 Users Rate Tracebit Community Edition?

  • Quality of Support: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 10.0/10 (Category avg: 9.0/10)

Who Is the Company Behind Tracebit Community Edition?

  • Seller: Tracebit
  • Year Founded: 2022
  • HQ Location: London, GB
  • Twitter: @tracebit_com
    312 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    44 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of Tracebit Community Edition?

Forestall ISPM

Forestall is an agentless Identity Security Posture Management (ISPM) and Identity Visibility and Intelligence Platform (IVIP). It helps security, IAM, and IT teams discover identity exposures, map privilege escalation and attack paths, and reduce identity risk across on-prem and cloud: Active Directory, Microsoft Entra ID, Microsoft 365, AWS, Azure, and Google Cloud. Coverage spans human identities, service accounts, non-human identities (NHI), and AI agent identities. Deployment is read-only and takes about an hour, with no admin privileges and no endpoint agents. Teams get prioritized, fix-first remediation guidance and audit-ready compliance reporting aligned to ISO 27001, NIST, CIS, STIG, PCI DSS, SAMA, NCA ECC, and UAE IAR.

Average Rating: 5.0/5.0

Total Reviews: 1

Who Is the Company Behind Forestall ISPM?

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Forestall ISPM?

Gurucul

Gurucul is the only cost-optimized security analytics company founded in data science that delivers radical clarity about cyber risk. Our REVEAL security analytics platform analyzes enterprise data at scale using machine learning and artificial intelligence. Instead of useless alerts, you get real-time, actionable information about true threats and their associated risk. The platform is open, flexible and cloud native. It conforms to your business requirements so you don't have to compromise. Our technology has earned us recognition from leading industry analysts as the most Visionary platform and an Overall leader in product, market and innovation. Our solutions are used by Global 1000 enterprises and government agencies to minimize their cybersecurity risk. To learn more, visit Gurucul.com

Average Rating: 3.0/5.0

Total Reviews: 2

How Do G2 Users Rate Gurucul?

  • Quality of Support: 8.3/10 (Category avg: 9.1/10)
  • Ease of Use: 9.2/10 (Category avg: 9.0/10)

Who Is the Company Behind Gurucul?

  • Seller: Gurucul
  • Year Founded: 2010
  • HQ Location: El Segundo, US
  • Twitter: @Gurucul
    1,321 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    288 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 50% Large, 50% Medium

What Do G2 Reviewers Say About Gurucul?

AI-generated summary from verified user reviews

Pros
  • Users find that Gurucul’s alerting system effectively reduces alert fatigue by prioritizing high-risk threats.
  • Users find that Gurucul's analytics reduce alert fatigue by prioritizing high-risk threats effectively, enhancing security operations.
  • Users value the self-explanatory dashboard that comprehensively addresses security posture and ensures reliable log ingestion.
  • Users find the dashboard self-explanatory and reliable, comprehensively covering security posture without data loss.
  • Users value the data protection features of Gurucul, ensuring reliable log ingestion and a robust security posture.
Cons
  • Users report that alerts take significant time to populate on the Gurucul console, causing delays in threat detection.
  • Users find the tedious cloud dependency challenging, impacting the efficiency of utilizing cloud-based security analytics.
  • Users find the complex parsing of Gurucul's threat intel feeds results in slow alert population on the console.
  • Users face deployment difficulties when moving security data to the cloud, hindering cloud analytics utilization.
  • Users struggle with ineffective alerts from Gurucul, as they take too long to populate on the console.

What Are Recent G2 Reviews of Gurucul?

Resmo

All in one platform for SaaS app and access management for modern IT teams. Streamline app discovery, user offboarding, access reviews, and cost tracking.

Average Rating: 5.0/5.0

Total Reviews: 9

How Do G2 Users Rate Resmo?

  • Quality of Support: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 9.7/10 (Category avg: 9.0/10)

Who Is the Company Behind Resmo?

  • Seller: Resmo
  • Year Founded: 2022
  • HQ Location: Dover, US
  • Twitter: @resmoio
    1,204 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    2 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 60% Small, 30% Medium

What Are Recent G2 Reviews of Resmo?

What Are G2 Users Discussing About Resmo?

The Illusive Platform

lllusive continuously discovers and automatically remediates privileged identity risks that are exploited in all ransomware and other cyberattacks. Despite best-practice investments to protect identities, including deployment of PAM and MFA, 1 in 6 enterprise endpoints holds exploitable identity risks. Illusive makes it easy for security teams to get visibility into the vulnerable identities sprawled across an organization’s endpoints and servers, then eliminate them or deploy deception-based detection techniques as a compensating control to stop attackers. Illusive has participated in over 140 red team exercises and has never lost one! Founded by nation state attackers, Illusive’s technology is trusted by large global financials, retailers, services organizations, and pharmaceuticals.

Average Rating: 4.0/5.0

Total Reviews: 1

How Do G2 Users Rate The Illusive Platform?

  • Quality of Support: 8.3/10 (Category avg: 9.1/10)
  • Ease of Use: 6.7/10 (Category avg: 9.0/10)

Who Is the Company Behind The Illusive Platform?

  • Seller: Proofpoint
  • Year Founded: 2002
  • HQ Location: Sunnyvale, CA
  • Twitter: @proofpoint
    31,157 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    5,261 employees on LinkedIn®
  • Ownership: NASDAQ: PFPT

Who Uses This Product?

  • Company Size: 100% Small

What Are Recent G2 Reviews of The Illusive Platform?

AD-Phoenix

AD-Phoenix© redefines enterprise identity resilience by delivering an automated, end-to-end Active Directory (AD) Forest recovery. Designed specifically for IT administrators and infrastructure engineers, this platform streamlines Bare Metal Recovery (BMR) of Domain Controllers. It automates multi-domain Forest recovery and enforces rigorous threat containment across both on-premises hypervisors (Microsoft Hyper-V, VMware ESXi), physical hardware (HPE iLO and DELL iDRAC) and Microsoft Azure. Whether executing an on-premises recovery, a hybrid lift-and-shift, or a cloud restoration into an isolated virtual network, AD-Phoenix© minimizes your Recovery Time Objective (RTO) while ensuring clean database recovery and a fully converged replication topology.

Who Is the Company Behind AD-Phoenix?

Akamai Account Protector

Akamai Account Protector is a comprehensive security solution designed to safeguard user accounts from abuse throughout their entire lifecycle. By leveraging machine learning and a rich dataset of risk and trust indicators, it accurately assesses the legitimacy of user requests, effectively preventing account takeovers and identity theft. Key Features and Functionality: - Lifecycle Protection: Evaluates user risk at every stage, from account creation to post-login activities such as account updates, password changes, and payments. - Advanced Detection Mechanisms: Utilizes machine learning to detect anomalies in user behavior, identifying potential threats based on profiles and risk signals. - Real-Time Risk Scoring: Assigns risk scores to user requests, enabling immediate and appropriate responses to potential threats. - Adaptive Response Actions: Implements customized actions such as blocking, alerting, or allowing requests based on the assessed risk score. - Continuous Learning: Incorporates legitimate user behavior into its profiling to enhance future assessments and reduce false positives. Primary Value and User Benefits: Akamai Account Protector addresses the critical need for robust account security by: - Preventing Financial Losses: Mitigates the financial impact associated with fraudulent activities and account takeovers. - Maintaining Customer Trust: Ensures a secure user experience, preserving the integrity and reputation of businesses. - Enhancing Operational Efficiency: Reduces the burden on security teams by automating threat detection and response processes. - Adapting to Evolving Threats: Continuously updates its detection capabilities to counter sophisticated adversarial bot attacks and other emerging threats. By integrating Akamai Account Protector, organizations can effectively defend against account abuse, ensuring the safety of user accounts and the overall security of their digital platforms.

Who Is the Company Behind Akamai Account Protector?

  • Seller: Akamai Technologies
  • Year Founded: 1998
  • HQ Location: Cambridge, MA
  • Twitter: @Akamai
    115,251 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    10,658 employees on LinkedIn®
  • Ownership: NASDAQ:AKAM

Attivo Networks Identity Threat Detection and Response

Attackers are targeting credentials, privileges and the systems that manage them. Identity Threat Detection and Response solutions are designed to detect and derail identity-based attacks.

Who Is the Company Behind Attivo Networks Identity Threat Detection and Response?

  • Seller: Attivo Networks
  • Year Founded: 2013
  • HQ Location: Mountain View, US
  • Twitter: @AttivoNetworks
    3,653 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    3,529 employees on LinkedIn®

AuthMind

The AuthMind Agentic AI Identity Observability & Protection Platform secures agentic AI, non-human, and human identities by observing real access paths across every environment. By combining identity and system events with network, cloud, and application/service logs, AuthMind maps all known and unknown AI agents, NHIs, and human identities, exposing blind spots, eliminating shadow access, and unifying identity risk, combining identity posture management (ISPM) with real-time advanced identity threat detection (ITDR).

Who Is the Company Behind AuthMind?

  • Seller: AuthMind
  • Year Founded: 2020
  • HQ Location: Washington DC Metro Area, US
  • LinkedIn® Page: www.linkedin.com
    53 employees on LinkedIn®

Authomize

Authomize protects organizations from identity-based cyberattacks with the first Identity Threat Detection and Response (ITDR) Platform. Authomize collects and normalizes data of identities, access privileges, assets, and activities from cloud services, applications, and IAM solutions in order to detect, investigate and respond to identity risks and threats. Customers use Authomize to gain visibility of actual access, achieve least privilege across cloud services and applications, secure their IAM infrastructure, and automate compliance and audit preparations.

Average Rating: 4.5/5.0

Total Reviews: 1

Who Is the Company Behind Authomize?

  • Seller: Authomize
  • Year Founded: 2020
  • HQ Location: Alpharetta, US
  • LinkedIn® Page: www.linkedin.com
    5 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Large

What Are Recent G2 Reviews of Authomize?

BloodHound Enterprise

The problem of Attack Path Management requires a fundamentally different, unique methodology designed to help organizations understand, empirically quantify impact, and eliminate identity-based Attack Path risks.

Who Is the Company Behind BloodHound Enterprise?

Cayosoft Guardian Protector

Guardian Protector is a free, always-on threat detection and change monitoring solution for Active Directory, Entra ID, M365, and Intune. It provides continuous, real-time visibility across hybrid identity environments, instantly alerting teams to risky changes like privilege escalation, dormant account activation, and GPO tampering. Agentless, audit-ready, and deployed in minutes. Real-time threat detection – Catch identity-layer risks as they occur: privilege escalations, dormant account reactivation, GPO tampering, dangerous policy edits, and more. Automatic Alerts – Instantly flags changes detected across hybrid environments. Provides who, what, when, and where context for faster triage. Harden Identity Posture – Identify and remediate existing misconfigurations and attack pathways that can lead to tenant or domain compromise. Hybrid change monitoring – One stream of truth across AD + Entra ID and key Microsoft 365 services for complete context. Continuous visibility—not snapshots – Ditch static point-in-time scans. Guardian Protector watches continuously, so you don’t miss what happens after the report is made. Agentless deployment – Nothing to install on domain controllers or endpoints. Get value fast, keep overhead low. Zero-cost, zero-hassle – Our free forever tier is designed for security-conscious IT pros who need coverage now. Audit-ready – Centralized logs and built-in reporting to satisfy auditors and streamline investigations.

Who Is the Company Behind Cayosoft Guardian Protector?

  • Seller: Cayosoft
  • Year Founded: 2018
  • HQ Location: Columbus, US
  • LinkedIn® Page: www.linkedin.com
    85 employees on LinkedIn®
Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024