Identity Detection & Response

Stop identity-based attacks before they spread

Detect account takeover and insider threats, contain compromised accounts autonomously, and respond faster with identity security that connects signals across your entire environment.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

  • Item A
  • Item B
  • Item C

The challenge

Attackers don’t need to break in when they can log in

Threat detection alone isn’t enough once credentials are compromised. Attackers move fast, meaning organizations need to contain account takeover before damage spreads.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

  • Item A
  • Item B
  • Item C

5.07M

Global average cost of attacks abusing valid accounts

(IBM Cost of a Data Breach 2026)

243 days

Mean time to contain breaches that abused valid accounts

(IBM Cost of a Data Breach 2026)

IDTR solution

Identity compromise shows up in the inbox, in a SaaS login, or moves through the network. Darktrace applies the same understanding of normal behavior everywhere identity is at risk.

How ITDR works

Detect, contain, and recover from identity-based attacks in a single motion

Bridge identity detection, autonomous response, and recovery with behavioral security powered by Adaptive AI.

Detect identity-based attacks instantly

Adaptive AI continuously analyzes login patterns, administrative activity, session behavior, and access requests against each identity's established baseline, surfacing account takeover, insider threat, and lateral movement that rule-based tools miss.

Respond autonomously to contain compromise

The moment behavior crosses the line, Darktrace takes an autonomous, fully configurable response – session termination, forced re-authentication, temporary access restrictions – before an attacker can exfiltrate data or move laterally.

Recover and audit the blast radius

Recovery workflows restore normal access and reconstruct exactly what was touched or exfiltrated during the compromise window, so teams can close out an incident with evidence, not guesswork.

Discover the Darktrace difference

Read the solution brief

Identity-based network security

Contain compromised accounts before they escalate into network-wide compromise

Identity Detection & Response within Darktrace / HYBRID NETWORK connects identity behavior to network, cloud, and OT context.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

  • Item A
  • Item B
  • Item C

See identity misuse in the context of the network

Identity behavior – logins, privilege use, access patterns – is understood within the same Unique Behavioral Profile as the rest of the hybrid network, so credential misuse doesn't hide as just another log source.

Contain compromised accounts before lateral movement

When an account deviates from its established pattern, Darktrace correlates it with everything else happening in the environment and takes autonomous, configurable action to contain it before an attacker can move laterally.

One investigation, not a handoff

Real-Time AI Analyst investigations tie identity and network activity together end to end, so a compromised account is contained as part of one investigation, not passed between siloed identity and network tools.

Darktrace Filters

Identity-based email security

Contain account takeover before attackers exploit access

Identity Detection & Response within Darktrace / EMAIL extends detection into autonomous containment across email, SaaS, and cloud.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

  • Item A
  • Item B
  • Item C

Detect account takeover as it happens

Behavioral baselines for every account surface unusual login patterns, administrative activity changes, session token misuse, and adversary-in-the-middle indicators before traditional rules trigger.

Respond and recover at machine speed

Autonomous response – session termination, forced re-authentication, temporary access restrictions – contains compromised accounts across email, SaaS, and cloud, with recovery capabilities to restore access and audit what was touched or exfiltrated.

Bridge detection and response, without the handoff

Most email security vendors detect ATO but don't respond to it. Real-Time AI Analyst drives the same investigation that spotted the anomaly straight into the response, cutting the handoff latency between siloed tools.

Darktrace Filters
Darktrace delivered unique, enterprise-wide security detecting and responding to cloud-based attacks that others products missed, from malicious insiders and external attacks.”
Operations, Real Estate

See what Darktrce finds

Evaluate in your environment today

Customer stories

Hear from our customers

See how organizations across all sizes and industries are relying on Darktrace to get proactive about identity security.

This is some text inside of a div block.

This is some text inside of a div block.

Darktrace / EMAIL Recognized by Gartner®

Darktrace is a Leader in the 2025 Gartner® Magic Quadrant™ for Email Security Platforms, delivering AI-native protection, superior customer experience, and strong integrations.

This is some text inside of a div block.

This is some text inside of a div block.

Darktrace / EMAIL Recognized by Gartner®

Darktrace is a Leader in the 2025 Gartner® Magic Quadrant™ for Email Security Platforms, delivering AI-native protection, superior customer experience, and strong integrations.

Read report

Stronger as part of the Darktrace Behavioral Defense Platform

The Darktrace Behavioral Defense Platform provides unified visibility, continuous behavioral monitoring, and autonomous response across your entire enterprise – so you can secure AI, people and infrastructure in real time.

Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur.

  • Item A
  • Item B
  • Item C

Frequently asked

questions

How does identity-based security differ from traditional perimeter-based security?

The evolution from traditional security to the modern zero trust model reveals an important shift in cybersecurity strategy, spurred by today's complex cyber-threat landscape. Traditional perimeter-based security, often called the castle-and-moat model, defends the network edge with tools such as firewalls and VPNs. It assumes implicit trust for anything within the perimeter, so that once a cyber criminal breaches this defense, they gain almost unfettered access, enabling lateral movement and data exfiltration. This inherent internal trust is its primary weakness.

In contrast, the modern zero trust model makes identity the new control plane. Its core principle is "never trust, always verify." It demands explicit authentication and authorization for every access request, regardless of origin. This approach takes into account that perimeters are dissolving in a distributed, hybrid-cloud environment. Access decisions are dynamic, considering account user identity, device context, and environmental factors. Microsegmentation limits potential breaches, offering comprehensive security for data and applications.

Key differentiators include a focus shift from protecting the network to safeguarding the user, entity, and data, moving from implicit internal trust to explicit verification for all. It also expands coverage from just the corporate network to a global, multi-cloud environment.

To make zero trust security effective at an enterprise scale, AI is essential. It continuously learns what normal operations look like for an enterprise and detects deviations from this normality as possible anomalies. The technology enables real-time detection, supports dynamic enforcement of security policies, and facilitates automated responses to cyber-attack attempts.
1. Monitor authentication patterns

ATO attacks often start with malicious logins using stolen credentials. By continuously monitoring login behaviors and looking for anomalies, such as an unusual IP address, abnormal login times, or multiple failed login attempts, security teams can quickly spot signs of an ATO attack. Advanced identity security solutions can help track these patterns across cloud environments and on-premises systems, offering real-time alerts for suspicious activities.

2. Leverage Multi-Factor Authentication (MFA)

While MFA is fundamental in preventing unauthorized access, it’s essential for detecting ATO attempts post-authentication. Even with MFA in place, attackers can still attempt social engineering or phishing attacks to bypass these defenses. Security teams must implement additional layers, such as continuous user monitoring and behavioral analysis, to spot abnormal actions within an authenticated session.

3. Utilize Cloud Access Security Brokers (CASBs)

CASBs help monitor user access to cloud services and enforce security policies. Although they are valuable for ensuring compliance, they also offer critical visibility into cloud-based ATO attempts. By integrating CASBs with other security solutions, security teams can gain a more holistic view of user activity, identifying threats that span multiple applications and cloud environments.

4. Analyze user behavior

Identity security solutions that offer user behavior analytics can identify unusual patterns of activity, such as access to sensitive data or resources outside of typical user behavior. These tools analyze the context around each login attempt and flag any deviations from normal usage, helping security teams detect ATO attacks that bypass traditional security measures like MFA.

5. Deploy advanced endpoint protection

Sophisticated ATO attacks may involve lateral movement across networks once an attacker has gained access to an account. Endpoint protection tools, combined with network monitoring and intrusion detection systems, can help detect malicious activities that occur after authentication, such as data exfiltration or system manipulation.

6. Integrate identity security solutions

One of the biggest challenges security teams face in detecting ATO attacks is the fragmentation of identity security solutions. Many organizations use Single Sign-On (SSO) or Active Directory (AD) management tools, which are limited in their ability to detect threats across hybrid and multi-cloud environments. By integrating IAM solutions with a broader suite of security technologies, teams can bridge the gaps and gain comprehensive visibility to identify and prevent ATO attacks.

Detecting ATO attacks requires a layered, multi-faceted approach that integrates advanced technologies, behavioral monitoring, and continuous oversight. While traditional security measures, such as MFA, can help prevent unauthorized access, organizations must also address blind spots and integrate tools that provide visibility into post-authentication activity and across all layers of their infrastructure. With a comprehensive approach, security teams can more effectively detect and respond to ATO attacks before they cause significant harm.

What are the common indicators of insider threats related to user identities?

Insider threat detection poses a significant challenge in modern cybersecurity, as the activity originates from accounts within an organization's trusted boundaries.

Subtle shifts in established user behavior are often indicators of insider threat compromise — one common sign is the emergence of anomalous access patterns. This includes logins at unusual hours or from new locations, and attempts to access files or systems beyond a user's regular job functions. Suspicious data movement is another critical indicator, seen in sudden, significant increases in data downloads or transfers, or a user accessing highly sensitive files for the first time without a clear business justification.

Privilege and account changes also warrant scrutiny. These activities may involve attempts to escalate user privileges, creating new accounts without proper authorization, or unauthorized alterations to security groups. Within SaaS and cloud environments, examples of misuse include unusual email forwarding rules designed to exfiltrate information and altering permissions in shared cloud documents or folders in ways that deviate from standard procedures.

Detecting these subtle anomalies demands advanced capabilities. A multi-layered artificial intelligence approach establishes a unique pattern of life for every user, device, and application across the environment. Continuous learning enables the AI to spot minute changes — such as an employee's account suddenly behaving like an external threat actor — which would typically evade traditional, rule-based security tools. Such sophisticated analysis is crucial for proactively identifying and mitigating insider cyber-threats before they escalate.

What are the key performance indicators (KPIs) that can be used to measure the success of an identity security deployment?

Measuring the success of an identity security deployment is essential for demonstrating tangible risk reduction, calculating return on investment, and proving an improved security posture to leadership. Clear metrics are needed to measure the effectiveness of any security strategy. KPIs can be broadly categorized into two areas — security outcome KPIs and operational efficiency KPIs.

The most definitive security outcome KPI is a Reduction in Identity-Related Breaches. This directly reflects the effectiveness of the deployed controls in preventing compromise. Tracking the Mean Time to Detect (MTTD) and Mean Time to Remediate (MTTR) is also vital. These metrics demonstrate the speed at which identity-based cyber-attack attempts are identified and neutralized, thereby minimizing potential damage.

Alert Fatigue Reduction is a critical operational efficiency metric, indicating a decrease in the volume of low-priority, false-positive alerts. This decrease allows teams to concentrate on genuine, high-fidelity incidents rather than sifting through noise. Another essential metric is the Autonomous Response Rate, which measures the number and percentage of threats that are automatically contained without requiring direct human intervention.

Platforms like Darktrace / RESPOND directly improve these KPIs through multi-layered AI. The AI significantly lowers MTTR by providing an Autonomous Response capability that neutralizes threats in progress. It also drastically reduces alert fatigue by investigating events and presenting only the most critical, high-fidelity incidents for human review, empowering security teams to operate with greater focus and efficiency.

What are the key considerations for securing nonhuman identities, such as service accounts and bots?

Nonhuman identities, such as APIs, service accounts, CI/CD scripts, and IoT devices, present a growing and often invisible attack surface. These machine identities now outnumber human users by more than 80 to one, and a staggering 97% of them possess excessive privileges. This scale creates a significant vulnerability, as a compromise can lead to widespread unauthorized access across an organization's digital infrastructure.

These nonhuman identities come with unique challenges. Visibility gaps are common, as identities are often undocumented, unmanaged, and lack clear ownership within an organization. Many rely on static, exposed credentials, such as hard-coded keys or nonexpiring tokens. If these are stolen, they can provide threat actors with persistent access. Furthermore, these identities are frequently granted far more access than their functions require, directly violating the principle of least privilege and expanding the potential blast radius of a cyber-attack.

A robust strategy for securing nonhuman identities begins with comprehensive discovery and inventory. Organizations must use specialized tools to map all nonhuman identities, their associated credentials, and their exact permissions. Following this, life cycle management for credentials is essential, involving the implementation of automated processes for their creation, regular rotation, and secure retirement. Continuous behavioral monitoring for these machines is necessary to detect when an identity deviates from its expected function, indicating potential misuse.

Applying multi-layered AI to this machine identity problem is ideally suited to its scale and complexity. Platforms like Darktrace / RESPOND learn the specific, expected behavior of every service account and API. This historical data enables the AI to instantly detect when one of these identities is compromised or misused, ensuring a rapid response before it can be leveraged in a broader cyber-attack.