Identity Threat Detection and Response (ITDR) ↗
The Identity Threat Detection and Response (ITDR) add-on delivers comprehensive identity analytics and proactive posture management capabilities to secure organizational environments against identity-based threats. By integrating automated asset classification, behavior-based detection rules, and dynamic access policies, ITDR enables you to continuously monitor risk exposure, uncover anomalous activity, and enforce directory protections.
The ITDR add-on includes the following capabilities:
- User Risk View which provides additional information about the asset for easy uncovering of hidden threats.
- Risk Management Dashboard to help you review the risk exposure of the organization and enable faster decision making.
- Automated and customizable Asset Role classification based on constant analysis of the users in your network. You can edit and manage the User Asset Roles to meet the needs of your organization.
- Detection rules which monitor identity and authentication activity to identify identity-based threats, such as compromised accounts, privilege escalation, and anomalous access, and trigger issues when suspicious behavior is detected. See a complete list of the Analytics rules.
- Dedicated view for quickly reviewing all identity related issues at a glance under Modules → Identity Security → Issues → Threats.
- Active Directory Security Posture Management (AD-SPM) which scans your infrastructure to uncover security vulnerabilities and misconfigurations, including weak and compromised passwords, across all identity types and provides targeted remediation steps. For more information, see Improve Active Directory Posture with AD-SPM.
- Conditional Access Policy which enforces dynamic, context-driven access control by evaluating real-time authentication requests against user-centric security contexts and risk levels to immediately allow, block, or require multi-factor authentication. For more information, see Enforce dynamic access control with CAP.
- LDAP protection which analyzes and acts upon suspicious LDAP queries received by the Domain Controller, to detect and block Active Directory reconnaissance attacks. For more information, see Prevent malicious LDAP queries.
- Remediation actions using the Cortex Response and Remediation content packs, a collection of automated playbooks that enable you to focus on high-priority threats while automating repetitive tasks.\
For additional remediation capabilities, see the Idira documentation.