TL;DR: Identity-based attacks now evade endpoint, cloud and network tooling because credentials remain the leading initial access vector, cited at 38% of incidents in Verizon’s 2024 DBIR, while identity behaviour often unfolds across weeks, not single alerts, according to 8Layers. Real-time identity context, not raw log volume, is what closes that gap.
At a glance
What this is: This is a vendor analysis of ITDR that says identity attacks outpace tools built for logs, posture, or endpoint events because attackers move through multi-stage identity behaviour rather than isolated alerts.
Why it matters: It matters because IAM and security teams need detection that understands identity context, entitlement drift, and privilege escalation as a live attack chain, not just as disconnected events.
Context
ITDR is identity threat detection and response, meaning detection and response focused on identity activity rather than endpoints or generic logs. The article argues that identity has become the blind spot in environments where credentials, federation paths, and entitlement changes move faster than traditional monitoring can interpret.
For IAM practitioners, the key issue is not whether identity signals exist, but whether those signals are stitched together into a meaningful attack narrative before the attacker advances. The vendor positions ITDR as the missing layer between preventive posture tools and broad SIEM correlation.
The article’s practical claim is that identity attacks are often slow, quiet, and distributed across multiple systems. That makes the governance problem one of context retention and behaviour correlation, not simply alert volume.
Key questions
Q: What breaks when identity attacks are detected quickly but not contained quickly?
A: The control model breaks at the point where valid access still has enough authority to do damage. Fast detection does not prevent token abuse, overprivileged session activity or delegated access from spreading impact. If containment lags behind detection, identity security is measuring alert speed rather than limiting blast radius.
Q: Why do identity incidents need real-time behavioural context instead of raw logs?
A: Because raw logs show activity, not meaning. An authentication event only becomes useful when it is tied to the identity’s normal access patterns, entitlement history, and earlier correlated signals. Without that context, defenders get volume without insight and struggle to distinguish normal cloud identity churn from malicious movement.
Q: How do teams know whether identity-based detection is working?
A: Look for detections that correlate identity, behaviour, and privilege changes across environments, not just isolated alerts. A working programme should identify unusual pivots between identity types, flag access that no longer matches historical behaviour, and reduce time spent stitching together events after the fact.
Q: What should teams do when posture tools and SIEMs do not explain identity behaviour?
A: They should add identity-specific detection that can correlate authentication, entitlement, and session data over time. Posture tools show exposure and SIEMs aggregate events, but neither is enough on its own to expose identity attack campaigns. The missing capability is behavioural interpretation anchored in identity context.
Technical breakdown
Why identity attacks outlast individual alerts
Identity attacks rarely appear as a single event. They typically begin with credential abuse, then move through privilege escalation, lateral movement, and selective data access over days or weeks. Tools built to fire on isolated thresholds struggle because each event looks ordinary in isolation. ITDR is positioned to preserve the sequence, correlate identity behaviour over time, and treat the campaign as one evolving attack rather than five disconnected signals. In practice, that means the detection layer must understand identity state, not just identity events, if it is to expose multi-stage abuse before the attacker reaches impact.
Practical implication: monitor identity activity as a chain of related actions, not as separate alerts.
Why posture tools and SIEMs leave an identity context gap
Posture tools are preventive: they show misconfiguration, over-privilege, and exposure. SIEMs are broad aggregators: they collect logs but do not always resolve identity-specific meaning. The gap appears when a login, entitlement change, or session anomaly only becomes meaningful if it is tied to who the identity is, what it normally accesses, and what changed before the event. ITDR is designed to enrich the raw signal with identity context so the analyst sees behaviour, not just telemetry. Without that enrichment, the control plane can detect noise but miss malicious intent.
Practical implication: connect identity context to log data before expecting reliable detection or response.
How real-time identity behaviour changes the detection model
Real-time identity monitoring changes the detection model from static rule matching to behavioural reconstruction. The article’s core point is that identity incidents are better understood as multi-stage kill chains that unfold across sessions, identities, and resources. In that model, the system needs persistent context, temporal correlation, and response actions available at the moment of detection. This is not just better alerting. It is a different governance assumption: that the security team can still reconstruct meaningful identity activity after the fact. ITDR challenges that assumption by keeping the narrative intact as the attack develops.
Practical implication: prioritise identity telemetry platforms that retain state long enough to reconstruct attack progression.
Threat narrative
Attacker objective: The attacker wants to turn ordinary-looking identity behaviour into a sustained foothold that supports deeper access and eventual data compromise.
- Entry begins with stolen or abused credentials that let the attacker blend into normal authentication activity.
- Escalation follows through privilege abuse, entitlement drift, or movement across connected identity providers and cloud sessions.
- Impact emerges when the attacker combines identity access with later data access, often long before a conventional alert would have tied the stages together.
Breaches seen in the wild
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
- CISA Private-CISA GitHub leak 2026: A CISA contractor's public GitHub repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 200+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Identity security fails when it is treated as event correlation instead of behavioural continuity. The article is right that identity attacks unfold over time and across systems, but the deeper issue is that many programmes still assume the useful security object is the alert, not the attack narrative. That assumption breaks when access, entitlement, and session state mutate between detection points. The practitioner takeaway is that identity governance has to preserve continuity, not just visibility.
Identity context is the control plane, not an enrichment layer. Raw authentication logs are insufficient unless they are interpreted against entitlement history, normal user behaviour, and cross-IdP relationships. That is why identity-specific detection cannot be treated as a SIEM plugin or a posture add-on. The field needs to recognise that identity meaning is constructed, not observed in isolation. The implication is to design for context retention as a first-class control.
Identity attack campaigns expose the limit of flat-rule thinking. A rule engine that fires on one threshold at a time misses coordinated abuse that is deliberately distributed across days or weeks. This is not a tuning issue, it is a model mismatch. Security teams should interpret repeated medium-severity identity signals as evidence of sequence, not noise to be suppressed.
Continuous identity memory is becoming a governance requirement. The article highlights that the security team must still remember what happened months earlier when the next stage begins. That points to a broader governance shift: if identity activity can no longer be held in short-lived buffers, then the organisation needs persistent identity state as part of its detection fabric. Practitioners should treat memory depth as a security design decision.
Identity Threat Detection and Response should be judged by narrative reconstruction, not alert volume. One alert per attack is analytically more useful than one alert per signal because it changes how analysts reason about compromise. The field should move away from counting detections and toward measuring whether the platform can explain who, what, when, and how an identity attack unfolded. Practitioners should demand that level of reconstruction.
What this signals
Identity teams need continuous memory, not short log buffers. When the second stage of an identity attack may arrive weeks later, the security model has to preserve enough state to reconnect the earlier signals. That makes retention depth and cross-system correlation part of the control design, not an implementation detail.
Identity Threat Detection and Response changes the detection question from ‘what fired?’ to ‘what sequence is unfolding?’ That shift matters because attackers increasingly spread credential abuse, privilege escalation, and access over time to avoid threshold-based detections. Practitioners should evaluate whether their current stack can explain a campaign before it matures.
Identity context should sit beside alerting, not behind it. If investigators must rebuild who the identity was, what it could touch, and how it changed over time, the platform is not yet doing enough of the work. A useful programme reduces that manual reconstruction burden up front.
For practitioners
- Map identity telemetry to attack sequences Correlate authentication events, access changes, and session activity into one timeline so analysts can see a campaign rather than a stream of unrelated signals.
- Preserve identity context across retention windows Keep structured identity state long enough to connect today’s alert with behaviour that began days or weeks earlier across IdPs and cloud resources.
- Tune detections for campaign behaviour Review whether your rules detect isolated thresholds only, or whether they can recognise repeated low-severity identity signals as one coordinated intrusion.
- Attach entitlement and posture data to investigations Make sure investigators can see exposed privileges, compliance context, and response options at the point of triage instead of assembling them manually.
- Test whether alerts reconstruct the full story Use realistic identity attack scenarios to confirm that the platform explains sequence, causality, and affected identities rather than producing disconnected detections.
Key takeaways
- Identity attacks are increasingly operationalised as multi-stage campaigns, which makes isolated alerting structurally weak.
- The article’s central concern is that raw logs and posture signals do not provide enough identity context to explain malicious behaviour in time.
- Practitioners should focus on persistent identity state, behavioural correlation, and narrative reconstruction rather than on alert count alone.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 and MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | The article centres on identity abuse that begins with compromised or misused credentials. |
| NHI-05 — Overprivileged NHI | Privilege escalation and entitlement drift are core attack stages discussed in the piece. | |
| Recommendation — Correlate authentication events with identity context to detect abused credentials earlier. Review identity entitlements for excess privilege that would amplify attacker movement. | ||
| NIST CSF 2.0 | DE.CM-09 — Monitoring for Unauthorized Personnel, Connections, Devices, and Software | The article is fundamentally about detecting identity behaviour as it unfolds in monitored environments. |
| Recommendation — Expand monitoring to include identity-behaviour signals, not only infrastructure events. | ||
| MITRE ATT&CK | TA0006; TA0008 — Credential Access; Lateral Movement | The article describes credential abuse leading into lateral movement across identities and cloud sessions. |
| Recommendation — Map identity detections to credential access and lateral movement tactics to improve triage. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | The article argues logs alone are insufficient unless they are analysed with identity context. |
| Recommendation — Analyse identity audit data for correlated behaviour instead of reviewing events one by one. | ||
Key terms
- Identity Threat Detection and Response: Identity threat detection and response is the practice of finding misuse of credentials, unusual access patterns, and compromised identities across human and machine actors. For NHIs, it relies on telemetry from code, vaults, cloud services, and pipelines to detect abuse early enough to contain it.
- Identity context: The entitlement, ownership, and purpose information that explains why an action occurred and whether it was expected. For security operations, identity context turns raw alerts into decisions by showing which human or non-human identity acted and what it was allowed to do.
- Behavioral Correlation: Behavioral correlation is the process of linking seemingly minor identity events into one campaign using shared attributes such as IP ranges, device signals, timing, and account relationships. It is the control layer that turns noisy telemetry into a coherent investigative picture.
- Identity State: Identity state is the live condition of an account, token, certificate, or permission set at a given moment. It matters because a task can be complete while the real access remains active, stale, or overprivileged. Security teams should validate identity state rather than relying only on process completion.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org