Back to Glossary

Glossary Term

Identity Threat Detection & Response (ITDR)

Detecting and mitigating identity-based cyberattacks.

1 min read

Share this definition

Post it to your feed or send it to teammates.

Short definition: Detecting and mitigating identity-based cyberattacks.
1 min read

What it is

ITDR tools analyze risky login behavior, privilege escalation, lateral movement, and token misuse. They integrate with IAM, MFA, cloud identity platforms, and SIEM tools.

Why it matters

Identity is the new security perimeter. Attackers prefer stealing credentials instead of exploiting vulnerabilities.

How to reduce risk

  • Use adaptive MFA
  • Monitor impossible travel
  • Detect privilege escalation
  • Rotate service account keys
  • Audit identity configurations
  • Integrate ITDR with SOC processes

Related Terms

External Resources

  • Gartner Identity Threat Detection: https://www.gartner.com/en
  • Microsoft Entra Identity Protection: https://learn.microsoft.com/en-us/azure/active-directory/identity-protection/