ITDR
Identity Threat Detection and Response (ITDR) is the discipline that detects and stops attacks on identities. These include accounts, tokens, sessions, permissions and identity providers. It complements EDR and SIEM with signals that only arise in the identity layer.
GlossaryAllITDR
Context
ITDR complements EDR and SIEM with the identity view: sign-ins, tokens, OAuth consent grants, role changes, federation events. For the category view with use cases, response playbooks and Swiss regulation see ITDR: Identity Threat Detection and Response. See Token theft and session hijacking for specific attacks on the identity layer. For the SOC framework, see SOC as a Service Switzerland.
Where ITDR delivers the most value
- M365 and Entra ID environments with high attack pressure on mailboxes and OAuth apps.
- Environments federating into SaaS portfolios where Golden SAML and token attacks are realistic.
- Regulated customers (banking, healthcare, government) with traceability duties from revFADP (revised Federal Act on Data Protection), FINMA or ISG.
- Organisations with many privileged accounts where role changes and consent grants are hard to monitor manually.
Related terms