Cybersecurity

Attackers Are Logging In, Not Breaking In

Attackers Are Logging In, Not Breaking In
11:37

Identity Threat Detection and Response (ITDR) is a security capability that detects and responds to identity-based attacks, such as credential theft, session hijacking and account takeover, in real time. Unlike endpoint protection or identity management tools, ITDR monitors behavior after authentication, catching attackers who've already bypassed your perimeter using valid credentials.

Most mid-market businesses have endpoint protection in place. Many have email filtering, a firewall and some form of identity management. Leadership checks those boxes and assumes the environment is covered.

It isn't.

Credential misuse is the leading cause of breaches, according to Verizon's 2025 Data Breach Investigations Report. Attackers aren't breaking through your defenses. They're logging in. And once they're in with valid credentials, most security stacks go silent.

That silence is the gap ITDR closes.

What Is ITDR, and Why Does It Exist?

Identity Threat Detection and Response is a security capability that monitors what happens after a user authenticates. It detects credential abuse, session hijacking, privilege escalation and lateral movement that traditional tools can't see.

Gartner recognized ITDR as a distinct security category in 2022. The distinction matters. Identity and access management (IAM) controls who gets access. ITDR detects when that access is subverted, abused or stolen.

The two tools address different problems. IAM manages the front door. ITDR watches what happens inside.

ITDR specifically monitors for:

    • Suspicious logins from unusual locations or unfamiliar devices
    • Privilege escalation outside of normal change windows
    • Malicious inbox rules and email forwarding changes
    • Session token reuse from multiple locations
    • OAuth abuse and unauthorized application consent grants
    • Lateral movement between systems using legitimate authentication

These are the behaviors attackers rely on. Most of them don't trigger a single alert in a standard security stack.

The Scale of the Problem

The numbers aren't abstract. They reflect what's already circulating in the environments your business depends on.

According to the SpyCloud 2026 Identity Exposure Report, 65.7 billion identity records were recaptured in 2025, a 23% year-over-year increase. The Microsoft Digital Defense Report 2025 found that identity attacks increased 32% in the first half of 2025, with more than 97% involving password-based techniques such as spraying and brute force.

These aren't statistics about large enterprises. They reflect a credential market that affects organizations of every size.

The Snowflake breach in 2024 demonstrated the consequence clearly. Threat actor UNC5537 used infostealer-harvested credentials, some years old, to access approximately 165 customer environments. Accounts had no multi-factor authentication (MFA). The credentials still worked. There was no behavioral monitoring to flag the anomaly. The breach ran undetected.

Midnight Blizzard followed a similar path. Attackers used password spraying to access a legacy test account, then leveraged OAuth applications to read senior leadership email. Standard controls didn't catch it because the attacker looked like a legitimate user at every step.

The pattern is consistent: valid credentials, no behavioral monitoring, unrestricted access.

Why Your Current Security Stack Has a Blind Spot

Endpoint protection monitors devices. It watches for malware, suspicious processes and file-level changes. It does that job well.

What it doesn't do is monitor identity behavior across cloud platforms, SaaS applications and authentication systems. When an attacker uses a stolen session token to access Microsoft 365, the endpoint sees nothing unusual. There's no malware. No suspicious process. Just a user session that looks normal.

IAM enforces access policies at login. It doesn't evaluate behavior after access is granted. That was acceptable when attackers were on the outside trying to get in. Today's attackers log in first and move laterally second.

Microsoft 365 itself doesn't provide comprehensive behavioral monitoring out of the box. Default configurations leave gaps in identity threat detection that most organizations aren't aware of until they're reviewing a breach after the fact.

Gartner's March 2026 research confirms this directly: most security operations centers aren't currently equipped to detect identity-specific threats, leaving organizations with significant blind spots.

The gap isn't a failure of tools. It's a design limitation. Tools built for endpoint protection and access control were not designed to detect an attacker who looks like a legitimate user.

What ITDR Actually Does for Your Business

ITDR applies behavioral analytics to identity signals continuously. It establishes a baseline of normal activity for each user and flags deviations, regardless of whether the credentials being used are technically valid.

The practical outcomes are measurable. Solutions with mature ITDR capabilities achieve mean times to respond under five minutes and false positive rates below 5%. That matters for your security team. High false positive rates create alert fatigue, which causes real threats to be missed or delayed.

For your business specifically, ITDR delivers:

Visibility you don't currently have. Suspicious logins, mailbox rule manipulation, privilege escalation and forwarding changes are detected and surfaced in context, not buried in raw logs.

Faster containment. Research from Darktrace's Annual Threat Report found that 68% of organizations detect identity threats within 24 hours, but only 55% contain them effectively. That 13-point gap represents hours of unrestricted attacker access. ITDR automation closes it.

Protection that works after MFA. MFA protects against password-based attacks. It doesn't protect against session hijacking or token theft. An attacker who captures a valid session token can impersonate a user without triggering an MFA challenge. ITDR detects the behavioral anomalies that follow, even when MFA was in place at login.

Integration with Microsoft 365. ITDR monitors identity activity across Microsoft 365 tenants, including suspicious logins, rogue OAuth applications, malicious inbox rules and account compromise attempts, providing the coverage Microsoft's default configuration doesn't include.

The Timeline Is Compressing

The urgency isn't theoretical. Gartner projects that by 2027, AI agents will automate credential theft and reduce the time from exposure to exploitation by 50%. Unit 42's 2026 research found that AI-assisted attack simulations achieved full data exfiltration in as little as 25 minutes.

Detection gaps measured in hours are no longer acceptable. They're a business continuity problem.

Organizations that haven't established identity threat detection before 2027 will be operating with a known, widening gap against an accelerating threat. The cost of that gap is measured in business disruption, data exposure, regulatory penalties and reputational damage, not just security incidents.

Where To Start

You don't need a complete security overhaul to close this gap. You need an honest assessment of what you currently have.

Start by asking your IT provider or MSP four direct questions:

    • Do you provide identity threat detection, not just identity management?
    • What happens after a user authenticates? What are you monitoring?
    • How would you detect a compromised session token?
    • Is identity monitoring integrated into your response workflows?

If the answers are vague, the gap is real.

From there, the practical path is straightforward: assess your current identity visibility, identify where monitoring ends and behavioral detection doesn't begin, then implement ITDR as part of a layered security model alongside your existing endpoint and email controls.

ITDR doesn't replace your current stack. It fills the gap your current stack was never designed to address.

Identity Risk Is a Business Decision

The Snowflake, Midnight Blizzard and similar incidents each followed the same pattern. Valid credentials. No behavioral monitoring. Unrestricted access until the damage was done.

The question for leadership isn't whether identity threats are real. The data settles that. The question is whether your current security model accounts for them, and if not, what that exposure is costing you right now.

A strategy session with a provider experienced in identity threat detection gives you a clear view of your current gaps and a practical path to close them before they become incidents.

Start a Strategy Session

Frequently Asked Questions About ITDR

What is ITDR and how is it different from IAM?

ITDR detects and responds to active threats targeting user and machine identities. IAM controls who gets access to systems. ITDR monitors what happens after access is granted, detecting credential misuse, session hijacking, privilege escalation and lateral movement that IAM tools aren't designed to catch.

Can't MFA protect my business against credential-based attacks?

MFA protects against password-based attacks. It doesn't protect against session hijacking or token theft. An attacker who captures a valid session token can access your environment without triggering an MFA challenge. ITDR detects the behavioral anomalies that follow token theft, even when MFA was in place during the original login.

Why don't most MSPs include ITDR in their standard offering?

ITDR is a relatively new security category. Most managed service providers built their stacks around endpoint, email and network controls before identity-based attacks became the dominant threat vector. The market is expanding quickly, but standard MSP offerings have lagged behind the shift in attacker behavior.

What kinds of organizations need ITDR?

Any organization running Microsoft 365, Okta or another cloud-based identity provider has a meaningful identity attack surface. Mid-market organizations are particularly exposed because they face the same threat landscape as enterprises but typically without dedicated identity security resources.

How does ITDR support compliance and cyber insurance readiness?

ITDR maps directly to controls required by NIST CSF 2.0, covering the Detect and Respond functions. Cyber insurance carriers are increasingly asking about behavioral monitoring and identity-specific detection during underwriting. Organizations with documented ITDR capabilities are better positioned during renewals and less likely to face coverage exclusions tied to identity-related incidents.

How quickly should a business implement ITDR?

The urgency is real. Gartner projects that by 2027, AI agents will automate credential theft and reduce exploitation time by 50%. The practical starting point is a gap assessment against your current capabilities, followed by integration of identity monitoring into your existing detection and response workflows.

Similar posts

Be The First To Know

Stay up to date with the latest articles, announcements, and upcoming events, delivered straight to your inbox.