Identity threat detection and response (ITDR) products promise to catch attackers who log in with valid identities, but they come from very different starting points. Some grew out of Active Directory security, some out of identity providers, some out of extended detection and response (XDR) platforms, SIEMs or identity posture tools, and some from NHI security. Their coverage, detection quality and response capabilities vary accordingly. This vendor-neutral buyer's guide helps you define what you need to detect, compare products and test them against realistic attacks.
Key takeaways
- Map products against the identity systems you actually run: on-premises AD, Entra ID and other IdPs, cloud IAM, SaaS and non-human identities.
- Look for detection depth (directory, token and session attacks), identity context (privilege, normal behaviour, attack paths) and response actions (session revocation, credential resets).
- Check how ITDR fits with your SIEM, XDR and IdP native protections; avoid paying twice for the same detections.
- Test with simulated attacks in your environment rather than relying on vendor demos.
Define requirements
- Which identity systems must be covered? See the ITDR Guide for the attack surface.
- Which threats are your priority: help-desk social engineering, token theft, directory attacks, cloud privilege escalation, NHI misuse?
- Who will operate it: SOC, IAM team or both?
- What response automation is acceptable, and through which tools?
Capability areas
| Area | What to look for |
|---|---|
| Coverage | AD (domain controller telemetry), Entra ID and other IdPs, cloud IAM, major SaaS, PAM, and NHI sources |
| Detection | Credential attacks, Kerberos abuse, DCSync, MFA fatigue, token and session replay, persistence via app credentials and federation, privilege escalation |
| Identity context | Privilege tiering, normal behaviour baselines, attack path analysis, correlation of one person's or workload's identities across systems |
| Posture | Identity misconfiguration findings that reduce attack surface |
| Non-human identities | Baselines for service accounts, service principals, OAuth apps and API keys |
| Response | Session and token revocation, account disablement, forced reset, MFA re-registration, SOAR playbooks |
| Integration | SIEM and XDR export, ticketing, IdP and PAM APIs, shared signals |
Questions to ask vendors
- Which of our identity systems do you cover natively, and which only through logs we forward?
- Show detection of a stolen session cookie being replayed from a new device.
- Show detection of a new credential added to a privileged service principal.
- How do you baseline service accounts and alert on misuse without flooding us with false positives?
- Which response actions can you take directly, and how quickly do they take effect?
- What overlaps with our IdP's built-in protections and our XDR, and what do you add?
- Do you need agents on domain controllers? What is the operational and security impact?
Red flags
- Detections that are simply re-labelled IdP alerts with no added context.
- No coverage of non-human identities.
- Response limited to sending alerts.
- High false positive rates in the proof of concept with no tuning path.
Proof of concept
- Connect your main identity systems in a representative environment.
- Run safe attack simulations: password spraying, Kerberoasting, MFA fatigue, session replay, adding app credentials, adding a federation trust, service account interactive logon.
- Measure detection rate, time to detect, alert quality, false positives and investigation context.
- Test response actions end to end, including session revocation.
- Involve SOC analysts who will use it daily.
How NHI Mgmt Group can help
We provide independent requirements and evaluation support. Browse vendors in our products directory or contact us.
Related NHI Mgmt Group resources: ITDR Guide · IVIP and ISPM Buyer's Guide · Active Directory and Entra ID Hardening Guide · NHI Security Platform Buyer's Guide