Identity threat detection and response (ITDR) software detects identity-related threats and vulnerabilities, such as credential misuse and abuse, unapproved entitlements and privilege escalations, and other identity-related threats. Information security teams use this software as part of their threat detection initiatives, specifically geared toward the identity-related attack surface.
Identity threat detection and response (ITDR) software is different from identity and access management (IAM) software; IAM’s function is to prevent identity-related risks through proper user authentication and access up front, while ITDR identifies threats once systems have been compromised. ITDR is also different from insider threat management (ITM) software in that ITDR identifies credentials and privileges abuse, commonly from external parties that have identified and misused identity vulnerabilities, while ITM monitors the actions a threat actor takes such as downloading data they are not entitled to.
To qualify for inclusion in the Identity Threat Detection and Response (ITDR) category, a product must:
Monitor and detect potentially malicious identity and privileges activity
Identify identity-related misconfigurations
Investigate identity threats with contextual user information
Flag unauthorized accounts and excessive privileges