Best Identity Threat Detection and Response (ITDR) Software - Page 4

How Many Identity Threat Detection and Response (ITDR) Software Products Does G2 Track?

Total Products under this Category: 73

Category Stats (Oct 2026)

  • Average Rating: 4.57/5 The average rating of products in this category, based on all submitted ratings
  • Top Trending Product: Falcon Identity protection (+2.92%) - Among all products in this category, Falcon Identity protection recorded the largest rating increase compared to last month

Last updated: October 01, 2026

How Does G2 Rank Identity Threat Detection and Response (ITDR) Software Products?

Why You Can Trust G2's Software Rankings:

  • 30 Analysts and Data Experts
  • 3,900+ Authentic Reviews
  • 73+ Products
  • Unbiased Rankings

G2's software rankings are built on verified user reviews, rigorous moderation, and a consistent research methodology maintained by a team of analysts and data experts. Each product is measured using the same transparent criteria, with no paid placement or vendor influence. While reviews reflect real user experiences, which can be subjective, they offer valuable insight into how software performs in the hands of professionals. Together, these inputs power the G2 Score, a standardized way to compare tools within every category.

G2 Grid® for Identity Threat Detection and Response (ITDR) Software

G2 Grid® for Identity Threat Detection and Response (ITDR)  Software plotting products by satisfaction and market presence

Highlighted products: CrowdStrike Falcon Endpoint Protection Platform, Huntress Managed ITDR, Abnormal AI, Okta, Microsoft Defender for Identity, Guardz, IBM MaaS360, and Idira Identity Security Platform.

Underlying data: [Grid® JSON](https://www.g2.com/categories/identity-threat-detection-and-response-itdr/grids.json?focus%5B%5D=crowdstrike-falcon-endpoint-protection-platform&focus%5B%5D=huntress-managed-itdr&focus%5B%5D=abnormal-ai&focus%5B%5D=okta&focus%5B%5D=microsoft-defender-for-identity&focus%5B%5D=guardz&focus%5B%5D=ibm-maas360&focus%5B%5D=idira-identity-security-platform)

CredVerify

VeriClouds credential verification services help organizations detect compromised credentials through the whole customer lifecycle and limit the risk of account takeover attacks. VeriClouds uses the same data attackers do, proactively monitoring the dark web, receiving threat intelligence feeds of know data breaches and systematically reducing user‑centric risk. VeriClouds provides the safest approach to eliminate the biggest cause of massive data breaches - the weak and/or stolen passwords.

Who Is the Company Behind CredVerify?

Delinea Server Suite

Secure and comprehensive access control to on-premises infrastructure, centrally managed from Active Directory, minimizing risk across all Linux, UNIX, and Windows systems. Server Suite secures privileged access for on-premise environments. It allows humans and machines to seamlessly authenticate, enforcing least privilege with just-in-time privilege elevation, increasing accountability, and reducing administrative access risk. Delinea offers best in class advanced Active Directory (AD) Bridging for complex enterprise-scale AD architectures helping IT achieve a more robust risk posture, reduce costs, improve security, and reduce IT overhead.

Average Rating: 4.2/5.0

Total Reviews: 9

How Do G2 Users Rate Delinea Server Suite?

  • Quality of Support: 6.7/10 (Category avg: 9.1/10)
  • Ease of Use: 8.3/10 (Category avg: 9.0/10)

Who Is the Company Behind Delinea Server Suite?

  • Seller: Delinea
  • Year Founded: 2004
  • HQ Location: San Francisco
  • Twitter: @DelineaInc
    897 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,385 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 56% Large, 33% Medium

What Do G2 Reviewers Say About Delinea Server Suite?

AI-generated summary from verified user reviews

Pros
  • Users value the enhanced security provided by Delinea Server Suite, ensuring robust protection of their data.
  • Users value the ease of use of Delinea Server Suite, making implementation and identity management straightforward.
  • Users value the simplified identity management of Delinea Server Suite, enhancing security and ease of implementation.
  • Users find the implementation ease of Delinea Server Suite remarkable, facilitating streamlined identity and privilege management.
  • Users highlight the reliability of Delinea Server Suite, benefiting from consistent and secure access management.
Cons
  • Users find that access issues arise due to interface challenges, ineffective notifications, and inadequate customer support.
  • Users report notification issues that hinder effectiveness, along with concerns about reporting and customer support.
  • Users struggle with password compliance issues and suggest improvements for notifications and customer support.
  • Users find the interface and support lacking, particularly for password compliance notifications and reporting.
  • Users express concern over poor customer support, wishing for improvements in assistance and service quality.

What Are Recent G2 Reviews of Delinea Server Suite?

What Are G2 Users Discussing About Delinea Server Suite?

Experian Account Takeover (UK)

Experian's Account Takeover (ATO) service is designed to protect businesses and their customers from the escalating threat of account takeover fraud. As digital interactions increase, so do opportunities for cybercriminals to exploit vulnerabilities, leading to unauthorized access to various accounts, including banking, retail, and social media. Experian's comprehensive ATO solution offers a multi-layered defense to detect and prevent such fraudulent activities. Key Features and Functionality: - Enhanced User Profiles: Utilizes device intelligence technology to build detailed profiles of users' typical activities, aiding in the identification of anomalies. - Accurate Fraud Detection: Employs behavioral biometrics to analyze cognitive and behavioral patterns, enhancing the detection of suspicious activities. - Risk Alerts: Incorporates known fraud checks to flag accounts or devices with previous high-risk indicators. - Optimized Decision Making: Applies machine learning algorithms to assess login attempts, distinguishing between legitimate users and potential fraudsters. - Unified Access: Provides a single access point for monitoring customer interactions, ensuring consistent security measures across platforms. - Proactive Defense: Identifies emerging fraud vectors and develops strategies to mitigate them, reducing costs associated with false positives. - Seamless User Experience: Ensures that security measures do not disrupt the customer journey, maintaining a smooth and invisible protection layer. - Trustworthy Interactions: Fosters mutual trust between businesses and customers by safeguarding against fraud attacks. Primary Value and User Solutions: Experian's ATO service addresses the critical need for robust online security in an era where account takeover incidents have surged by 34% in recent years. By implementing this solution, businesses can effectively protect their customers from unauthorized access, thereby preserving customer trust and minimizing financial losses. The service's proactive and comprehensive approach ensures that organizations stay ahead of evolving fraud tactics, providing a secure and seamless online experience for users.

Who Is the Company Behind Experian Account Takeover (UK)?

  • Seller: Experian
  • Year Founded: 1826
  • HQ Location: Dublin, Ireland
  • Twitter: @Experian_US
    38,771 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    26,648 employees on LinkedIn®
  • Ownership: LSE: EXPNL

AI can help you find the answers. G2 helps you trust them.

Connect G2 to Claude or ChatGPT for answers grounded in G2's trusted reviews, comparisons, and pricing from real user insights.

How it works

GuruCul Identity Analytics

Identity is the new perimeter and securing identities, establishing privileged access policies, and implementing zero trust programs are critical to protect organizations from threat actors. The rise of credential theft, modern day insider threats, and privileged access misuse equates to security teams needing to baseline current access policies, monitor for identity threats, both internal and external, and work cross-functionally for continuous improvement.

Who Is the Company Behind GuruCul Identity Analytics?

  • Seller: Gurucul
  • Year Founded: 2010
  • HQ Location: El Segundo, US
  • Twitter: @Gurucul
    1,321 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    288 employees on LinkedIn®

Identity Confluence

Identity Confluence is an AI-powered Identity Security and Governance platform designed to eliminate identity blind spots and automate lifecycle management across cloud, on-premises, and hybrid environments. As organizations scale, identities expand beyond employees to include service accounts, API clients, bots, and machine workloads. Without centralized governance, these identities create excessive privileges and compliance risk. Identity Confluence unifies identity intelligence, governance automation, and compliance management into a single platform that enables enterprises to: 1. Gain full visibility into human and non-human identities 2. Automate onboarding, role transitions, and offboarding workflows 3. Conduct intelligent, risk-based access certification campaigns 4. Detect and remediate Segregation of Duties (SoD) violations 5. Enforce least privilege access across hybrid environments 6. Centralize audit evidence within a built-in Evidence Center 7. Integrate with 250+ enterprise applications for rapid deployment\ Built for modern Identity Security teams, Identity Confluence provides a clear understanding of who (and what) has access, why that access exists, and how to continuously govern and enforce it. The outcome: reduced identity risk, faster compliance cycles, streamlined audits, and scalable governance aligned with Zero Trust principles.

Who Is the Company Behind Identity Confluence?

Identity Rules

Identity Rules combines real-time Identity Threat Detection (ITDR) with continuous Identity Visibility & Intelligence (IVIP). Detect compromised accounts, dormant NHIs, and access anomalies across AD, Okta, AWS, Entra ID, and more.

Who Is the Company Behind Identity Rules?

Identity Security Insights

BeyondTrust Identity Security Insights is a cloud-native platform that provides a unified view of identities, entitlements, and privileged access across hybrid IT environments. It uses AI-driven analytics to uncover hidden attack paths, detect active identity-based threats, and provide prescriptive recommendations to harden an organization's overall security posture.

Who Is the Company Behind Identity Security Insights?

  • Seller: BeyondTrust
  • Year Founded: 1985
  • HQ Location: Johns Creek, GA
  • Twitter: @BeyondTrust
    14,335 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    1,750 employees on LinkedIn®

Identity Threat Detection and Response

🛡️ Mirket ITDR – Identity-Centric Threat Detection for the Modern Enterprise Mirket ITDR, the threat detection module of our unified Mentis Platform, empowers organizations to detect identity-based attacks before they escalate—whether it's a compromised credential, an insider threat, or an attacker already operating within the system. By combining AI-powered behavioral analytics, Cyber Threat Intelligence (CTI), and strategic deception techniques, Mirket ITDR turns your identity infrastructure into an intelligent detection surface—capable of spotting and stopping even the stealthiest adversaries. 🧬 What Sets Mirket ITDR Apart? Advanced Threat Detection: Identifies risky logins, credential misuse, lateral movement, privilege escalation, and behavioral anomalies—even if the attacker is already inside. Account Takeover (ATO) Protection: Detects and halts unauthorized access attempts, password stuffing, and MFA bypass attacks in real-time. Insider Threat Detection: Flags anomalous behaviors from trusted users, preventing data leaks or sabotage before it’s too late. Cyber Threat Intelligence (CTI): Uses live feeds to detect TOR exit nodes, proxy abuse, breached credentials, and high-risk geo/IP patterns. AI & Machine Learning: Continuously learns normal behavior, adapts to new attack strategies, and minimizes false positives over time. Threat & Certainty Scoring: Applies dual risk scores to each detection and user profile for accurate prioritization and automated actions. MITRE ATT&CK Mapping: Aligns detections to real-world attacker tactics like Persistence, Credential Access, and Privilege Escalation. Deception Technology: Deploys decoy credentials, honey accounts, and fake network shares to trap attackers without alerting them. MFA as Detection: Goes beyond protection—dynamically triggers MFA based on risk signals from ongoing sessions, unusual behaviors, or compromised environments. Automated, Risk-Based Response: Enforces MFA challenges, blocks accounts, revokes sessions, or escalates to security teams—automatically or via playbooks. 🔐 Built for Identity-First Security Mirket ITDR is purpose-built for today’s threat landscape—where identities, not just endpoints, are under attack. It works seamlessly alongside our MFA and IAM modules, or as an add-on to third-party identity providers, to bring Zero Trust, detection, and response together in one platform. 📊 Stay Ahead of Attackers—Even the Ones Already Inside Whether someone is attempting to use stolen credentials, escalate privileges quietly, or operate as a rogue insider—Mirket ITDR sees them, scores them, and stops them. Because identity is not just your perimeter—it’s your most valuable target.

Who Is the Company Behind Identity Threat Detection and Response?

LinuxGuard

LinuxGuard is the control plane for Linux identity — a continuous Identity Security Posture Management (ISPM) and Identity Threat Detection & Response (ITDR) platform purpose-built for the Linux estate, rather than adapted from a Windows-first or cloud-first tool . It gives security and infrastructure teams a single, always-current inventory of every human account, service identity, SSH key, sudo rule, and PAM configuration across on-prem, cloud, and hybrid Linux servers, scoring each identity from 0–100 with inline explanations of the risk factors behind the score . LinuxGuard maps privilege-escalation paths, flags NOPASSWD sudo rules and orphaned or shared SSH keys, detects configuration drift in real time, and maps MITRE ATT&CK-aligned signals for detection and safety-gated automated response. It also generates continuous, audit-ready compliance evidence mapped to NIS2, DORA, SOC 2, CIS, NIST, PCI-DSS, and ISO 27001, and integrates with existing SIEM, ticketing, and collaboration tools . LinuxGuard is certified SUSE Ready, Red Hat Certified Technology, and validated for Ubuntu LTS/Debian.

Who Is the Company Behind LinuxGuard?

ObserveID

AI-Driven Converged Identity Security Platform. Built for on-premises, multicloud and hybrid environments, ObserveID provides organizations with real-time visibility into identities, entitlements, access risks, and user behavior. The platform automates access reviews, compliance workflows, lifecycle management, and threat detection while reducing operational complexity and SaaS sprawl. ObserveID’s AI framework powers intelligent automation, behavioral analytics, and contextual insights through OBI, its embedded AI assistant that combines Generative AI, Agentic AI, and Model Context Protocol for secure and explainable identity operations. Key capabilities include: 1- Automated certifications and access reviews 2- Identity Intelligence and behavioral analytics 3- Non-Human Identity (NHI) visibility 4- Real-time threat detection 5- Compliance automation 6- Role mining and AI-assisted governance 7- 250+ integrations across cloud, SaaS, and on-prem systems

Average Rating: 5.0/5.0

Total Reviews: 1

How Do G2 Users Rate ObserveID?

  • Quality of Support: 10.0/10 (Category avg: 9.1/10)
  • Ease of Use: 10.0/10 (Category avg: 9.0/10)

Who Is the Company Behind ObserveID?

  • Seller: ObserveID
  • Year Founded: 2021
  • HQ Location: N/A
  • Twitter: @Observe_ID
    10 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    22 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 100% Medium

What Are Recent G2 Reviews of ObserveID?

Obsidian Security

Obsidian Security is the first truly comprehensive threat and posture management solution built for SaaS. Our platform consolidates data across core applications to help your team optimize configurations, reduce over-privilege, and mitigate account compromises and insider threats. Getting started with Obsidian takes just a few minutes—with no agents to deploy or rules to write.

Average Rating: 4.0/5.0

Total Reviews: 3

How Do G2 Users Rate Obsidian Security?

  • Quality of Support: 9.2/10 (Category avg: 9.1/10)
  • Ease of Use: 8.3/10 (Category avg: 9.0/10)

Who Is the Company Behind Obsidian Security?

  • Seller: Obsidian Security
  • Year Founded: 2017
  • HQ Location: Palo Alto, California, United States
  • Twitter: @obsidiansec
    1,094 Twitter followers
  • LinkedIn® Page: www.linkedin.com
    267 employees on LinkedIn®

Who Uses This Product?

  • Company Size: 67% Large, 67% Medium

What Do G2 Reviewers Say About Obsidian Security?

AI-generated summary from verified user reviews

Pros
  • Users commend the A1 customer support from Obsidian, which ensures smooth implementation and positive outcomes for SaaS security.
  • Users appreciate the implementation ease of Obsidian Security, thanks to dedicated customer support and a streamlined process.
  • Users highlight the effective onboarding support from Obsidian, enhancing the implementation experience for SaaS Security practitioners.
  • Users find Obsidian Security to offer a comprehensive solution that significantly enhances SaaS security efforts.
Cons
  • Users find that the dashboard issues hinder usability and fall short compared to current SSPM offerings.
  • Users find the inadequate threat analysis in Obsidian Security limits its effectiveness compared to other platforms.
  • Users find the limited reporting capabilities of Obsidian Security to be a hindrance in effectiveness and usability.
  • Users note issues with reporting and dashboard functionality, expressing a need for improvement in these areas.
  • Users feel the UX could be improved, particularly with reports and the functionality of certain dashboards.

What Are Recent G2 Reviews of Obsidian Security?

PasskeyBridge

Real-time identity threat response fusing four signal layers—carrier, credential, biometric, physics—in under 50ms. Zero PII.

Who Is the Company Behind PasskeyBridge?

Permiso

Permiso detects and protects against human and non-human identity threats across cloud and on-premise environments to provide modern threat detection for your modern attack surface. Permiso assesses exposure risk to harden the identity attack surface, and detects suspicious and malicious identity behavior across all environments. Permiso inventories all identities in identity providers, IaaS, PaaS and SaaS environments and strengthens authorization controls, enforces least privilege, and remove zombie identities. The platform boasts over 1,500+ unique signals to quickly detect suspicious and malicious access patterns and activity across all environments.

Who Is the Company Behind Permiso?

  • Seller: Permiso
  • Year Founded: 2020
  • HQ Location: Palo Alto, US
  • LinkedIn® Page: www.linkedin.com
    62 employees on LinkedIn®

Posture Management

Astrix Security's NHI Posture Management solution is designed to enhance organizational security by providing comprehensive visibility and control over non-human identities (NHIs) such as service accounts, API keys, and OAuth applications. By offering actionable risk scoring, dynamic access analysis, and breach likelihood assessments, this solution enables security teams to prioritize and remediate NHI risks effectively without disrupting critical processes.

Who Is the Company Behind Posture Management?

Brandon Summers-Miller
BS
Researched and written by Brandon Summers-Miller
Updated October 3, 2024