Loading...
Identity Threat Detection and Response (ITDR) tools watch the identity layer for the attacks that slip past prevention: stolen credentials, MFA fatigue and bypass, privilege escalation, risky OAuth grants, and accounts that have quietly been taken over. The premise is that attackers no longer break in, they log in, so the identity fabric (Active Directory, Entra ID, Okta, and the session tokens behind them) becomes the thing you actually defend. This category is for security teams that already run IAM and EDR but have no real-time view of identity misuse, and for CISOs who realized their SOC can see endpoints and network traffic yet goes dark the moment an attacker operates with valid credentials. ITDR fills that gap by baselining normal identity behavior, surfacing anomalies, and giving you a way to respond before lateral movement becomes a breach.
We cover 90 Identity Threat Detection and Response tools, 1 free and 89 commercial.
Accuracy and depth improve over time. Last reviewed Jul 2026. Is something off? Reach out.
Identity observability platform for incident response and threat detection
Detects infostealer infections by monitoring criminal marketplaces
Identity threat detection and response platform for users and NHIs
Maps GCP service account key permissions and access for incident response
Adaptive authentication platform with risk-based dynamic user challenges
Identity threat detection platform for account fraud and ATO prevention
Identity threat detection and response platform for SaaS, cloud, and on-prem
Cloud identity threat detection and response platform for human and non-human IDs
Device fingerprinting solution for fraud detection and user tracking
Identity observability platform unifying human, NHI, and AI agent identities
Identity observability platform for AI agents, NHIs, and human identities
Identity protection platform for human & non-human identities across clouds
Identity security platform for access monitoring and threat detection
Identity security platform with ISPM, SaaS policy mgmt, and dynamic authz
Identity attack path management platform for hybrid environments
Identity threat detection and response platform for cloud infrastructure
Identity risk mgmt platform for visibility, correlation & remediation
Identity security platform mapping attack paths and misconfigurations
Detects help desk impersonation & social engineering attacks in real time
Detects impersonation & social engineering attacks via device/network signals
Prevents account takeover attacks through predictive detection and real-time protection.
AI-driven identity threat protection using behavioral analysis & risk signaling
ITDR solution for educational institutions with phishing detection
Identity threat detection and response solution by Identity Automation
Common questions about Identity Threat Detection and Response tools, selection guides, pricing, and comparisons.
ITDR is a category of security tools that detect and respond to attacks targeting your identity infrastructure: credential theft, account takeover, MFA bypass, privilege escalation, and abuse of valid logins. Rather than preventing access the way IAM does, ITDR assumes credentials will eventually be compromised and monitors identity behavior in real time to catch misuse before it turns into lateral movement or a full breach.
IAM and PAM control who gets access and to what; they are prevention. EDR watches endpoints. ITDR sits in the gap none of them covers well: an attacker using stolen but valid credentials. It monitors directories like Active Directory and Entra ID, identity providers like Okta, and session tokens for signs of abuse. Think of IAM as the lock and ITDR as the camera that notices someone using a copied key.
Start with coverage of your actual identity stack: on-prem Active Directory, cloud identity providers, and SaaS. Check which attack techniques each detects (Kerberoasting, golden ticket, token theft, OAuth abuse, MFA fatigue) versus what it merely logs. Then weigh detection signal quality against alert noise, the depth of automated response, and how cleanly it feeds your SIEM and SOAR. A tool that buries analysts in low-confidence alerts undercuts its own value.
Many identity providers, XDR platforms, and SIEMs now ship ITDR-adjacent features, and for smaller environments that may be enough. Dedicated ITDR earns its place when you run hybrid identity (on-prem AD plus cloud), carry a real attack surface around privileged accounts, or have been burned by an identity-based incident. The honest test: can your current tools tell you, today, whether a valid login is an attacker? If not, a specialist tool is worth evaluating.
Ranked by real community upvotes and saves — never for sale. Featured placement is always labeled.