Loading...
Identity Threat Detection and Response (ITDR) tools watch the identity layer for the attacks that slip past prevention: stolen credentials, MFA fatigue and bypass, privilege escalation, risky OAuth grants, and accounts that have quietly been taken over. The premise is that attackers no longer break in, they log in, so the identity fabric (Active Directory, Entra ID, Okta, and the session tokens behind them) becomes the thing you actually defend. This category is for security teams that already run IAM and EDR but have no real-time view of identity misuse, and for CISOs who realized their SOC can see endpoints and network traffic yet goes dark the moment an attacker operates with valid credentials. ITDR fills that gap by baselining normal identity behavior, surfacing anomalies, and giving you a way to respond before lateral movement becomes a breach.
We cover 90 Identity Threat Detection and Response tools, 1 free and 89 commercial.
Accuracy and depth improve over time. Last reviewed Jul 2026. Is something off? Reach out.
Identity Security Posture Management platform for cloud identity protection
Identity security platform for AI users, builders, and agents across cloud envs
AI-powered ITDR platform detecting identity attacks across hybrid environments
AI-powered identity threat detection and response for cloud and SaaS environments
ITDR platform integrated with XDR for identity protection and threat detection
Identity threat detection and response platform for hybrid environments
Detects & blocks identity-based threats in real-time across hybrid environments
AI-powered identity visibility and threat detection solution
Monitors identities for threats and provides remediation recommendations.
Identity threat detection and response platform for Active Directory
Identity threat detection and response solution for account protection
Identity threat detection and response solution for Active Directory
Identity security platform for threat detection and access management
Microsoft 365 login protection against phishing pages and suspicious logins
AI-powered identity security platform for AD and Entra ID protection
Identity security platform protecting identities across attack chains
Cloud identity security platform for human, machine, and AI identities
Protects against account abuse across lifecycle using ML and risk indicators
Common questions about Identity Threat Detection and Response tools, selection guides, pricing, and comparisons.
ITDR is a category of security tools that detect and respond to attacks targeting your identity infrastructure: credential theft, account takeover, MFA bypass, privilege escalation, and abuse of valid logins. Rather than preventing access the way IAM does, ITDR assumes credentials will eventually be compromised and monitors identity behavior in real time to catch misuse before it turns into lateral movement or a full breach.
IAM and PAM control who gets access and to what; they are prevention. EDR watches endpoints. ITDR sits in the gap none of them covers well: an attacker using stolen but valid credentials. It monitors directories like Active Directory and Entra ID, identity providers like Okta, and session tokens for signs of abuse. Think of IAM as the lock and ITDR as the camera that notices someone using a copied key.
Start with coverage of your actual identity stack: on-prem Active Directory, cloud identity providers, and SaaS. Check which attack techniques each detects (Kerberoasting, golden ticket, token theft, OAuth abuse, MFA fatigue) versus what it merely logs. Then weigh detection signal quality against alert noise, the depth of automated response, and how cleanly it feeds your SIEM and SOAR. A tool that buries analysts in low-confidence alerts undercuts its own value.
Many identity providers, XDR platforms, and SIEMs now ship ITDR-adjacent features, and for smaller environments that may be enough. Dedicated ITDR earns its place when you run hybrid identity (on-prem AD plus cloud), carry a real attack surface around privileged accounts, or have been burned by an identity-based incident. The honest test: can your current tools tell you, today, whether a valid login is an attacker? If not, a specialist tool is worth evaluating.
Ranked by real community upvotes and saves — never for sale. Featured placement is always labeled.