Join our Newsletter — 33% off our NHI Course

ITDR in the SOC: what closes the identity detection gap?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: As cloud adoption grows, identity is becoming a top attack vector and traditional EDR and NDR tools are missing identity threats, according to Netwrix’s on-demand security masterclass on ITDR. The real issue is that SOC programmes still treat identity as a side signal, even though identity has become the frontline control plane for access and abuse.

Editorial analysis by NHI Mgmt Group, based on content published by Netwrix: “[Security Masterclass] Strengthen Your SOC with ITDR: Closing the Gaps Left by EDR and NDR”.

Key questions

Q: What breaks when SOC teams rely on EDR and NDR for identity threats?

A: They miss abuse that happens through legitimate identities, because endpoint and network telemetry can look normal while access is being misused.

Q: Why do identity-based attacks create blind spots in the SOC?

A: Because many identity attacks do not depend on malware or unusual traffic.

Practitioner guidance

  • Embed identity signals into SOC triage Correlate authentication, privilege use, and access anomalies with endpoint and network alerts so analysts can see identity abuse in context.
  • Define identity-specific detection logic Write detections for abnormal sign-ins, privilege misuse, token abuse, and unusual service-account behaviour rather than relying only on host-based indicators.
  • Create identity containment playbooks Map the response steps for suspicious account activity, including credential invalidation, session review, and privileged access suspension.

Bottom line: Identity threats can evade endpoint and network-centric monitoring when attackers operate through valid accounts, sessions, or tokens.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Identity is no longer a supporting signal in SOC operations. When cloud services, SaaS, and machine access become primary business dependencies, the identity layer becomes the path attackers use most often to bypass perimeter assumptions. EDR and NDR still matter, but they do not explain who should have access, who actually used it, or whether that use was legitimate. The practical conclusion is that identity telemetry must be treated as a first-class SOC data source.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: What should a SOC do immediately when identity abuse is suspected?

A: The SOC should move directly to containment by revoking tokens, ending active sessions, forcing reauthentication, and escalating privileged access review. Identity abuse can continue without malware or network anomalies, so waiting for endpoint confirmation wastes time. The fastest way to reduce impact is to interrupt the access path itself before the attacker expands privilege or reaches sensitive systems.

👉 Read our full editorial: Identity threats are outpacing EDR and NDR in the SOC



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Identity is no longer a supporting signal in SOC operations. When cloud services, SaaS, and machine access become primary business dependencies, the identity layer becomes the path attackers use most often to bypass perimeter assumptions. EDR and NDR still matter, but they do not explain who should have access, who actually used it, or whether that use was legitimate. The practical conclusion is that identity telemetry must be treated as a first-class SOC data source.

A few things that frame the scale:

  • 91.6% of secrets remain valid five days after the targeted organisation is notified, showing a critical gap in remediation procedures, according to Ultimate Guide to NHIs.
  • Only 5.7% of organisations have full visibility into their service accounts, according to Ultimate Guide to NHIs.

A question worth separating out:

Q: What should a SOC do immediately when identity abuse is suspected?

A: The SOC should move directly to containment by revoking tokens, ending active sessions, forcing reauthentication, and escalating privileged access review. Identity abuse can continue without malware or network anomalies, so waiting for endpoint confirmation wastes time. The fastest way to reduce impact is to interrupt the access path itself before the attacker expands privilege or reaches sensitive systems.

👉 Read our full editorial: Identity threats are outpacing EDR and NDR in the SOC



   
ReplyQuote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21503
 

Identity telemetry is becoming a first-class SOC input, not a niche IAM feed. The traditional split between endpoint detection, network detection, and identity governance no longer matches how access is abused in cloud-heavy environments. When the attack path is a valid account, token, or privileged session, the SOC needs identity context at the same priority as host and network data. The practitioner conclusion is that identity detection cannot remain downstream of conventional telemetry.

A question worth separating out:

Q: How should teams respond when identity abuse is visible but EDR and NDR stay quiet?

A: Treat the identity event as a primary incident signal, not a secondary anomaly. Investigate the account or session, review recent privilege use, invalidate exposed credentials if needed, and determine whether the access path should be suspended before further movement occurs. The response should be driven by identity context, not by waiting for an endpoint alert.

👉 Read our full editorial: Identity threats are outpacing EDR and NDR in the SOC


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.