# What is Identity Threat Detection and Response (ITDR)?

> Identity threat detection and response is an industry label for the practices and capabilities used to detect, investigate, and contain attacks involving identities and identity infrastructure.

- Canonical URL: https://yellowcube.eu/glossary/identity-threat-detection-and-response/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Its scope can include human and workload accounts, credentials, authenticators, sessions, tokens, directories, identity providers, federation, privileges, and the policies that govern access.

ITDR correlates identity-specific evidence with endpoint, application, cloud, and network context. It looks for behaviors such as password spraying, suspicious token creation, unexpected role assignment, illicit application consent, authentication-policy changes, session theft, and abnormal use of valid accounts. Response may revoke sessions or credentials, disable an identity, remove unauthorized privileges, restore policy, isolate a system, and preserve evidence for the wider incident investigation.

### Key points

- **Key telemetry:** Authentication outcomes, token and session events, directory changes, privilege grants, application registrations, device enrollment, policy administration, and resource access.
- **Response actions:** Challenge or block access, revoke tokens, rotate credentials, disable accounts, remove persistence, reverse unauthorized changes, and escalate through incident response.
- **Program requirements:** Baseline expected identity behavior, protect and retain logs, define high-risk playbooks, test containment paths, and coordinate identity, security operations, and application owners.
- **Important limitation:** ITDR is not a standardized NIST control category, and product coverage varies. Missing logs, short retention, forged tokens, or activity outside integrated identity systems can leave serious blind spots.

### Related terms

[Identity and access management (IAM)](<https://yellowcube.eu/glossary/identity-and-access-management/>) · [Account takeover (ATO)](<https://yellowcube.eu/glossary/account-takeover/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [Incident response (IR)](<https://yellowcube.eu/glossary/incident-response/>) · [Privileged access management (PAM)](<https://yellowcube.eu/glossary/privileged-access-management/>) · [Identity provider (IdP)](<https://yellowcube.eu/glossary/identity-provider/>)

### Sources

[CISA on securing core cloud identity infrastructure](https://www.cisa.gov/news-events/news/securing-core-cloud-identity-infrastructure-addressing-advanced-threats-through-public-private) · [MITRE ATT&CK Identity Provider Matrix](https://attack.mitre.org/matrices/enterprise/cloud/identityprovider/) · [NIST SP 800-61 Rev. 3](https://csrc.nist.gov/pubs/sp/800/61/r3/final)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

