Identity Threat Detection and Response (ITDR)

When the attacker is
already logged in

Attackers log in with stolen credentials, abused OAuth tokens, and service accounts nobody revoked. From there they move through cloud, SaaS, and AI systems on the same paths your employees use. Mitiga baselines every identity, human and non-human, and surfaces active compromise before the blast radius grows.

Zero-Impact Breach Prevention, in runtime.

EDR protects the endpoint. Mitiga protects everything else cloud, SaaS, identity, AI, and third-party services.

Anticipate, disrupt, stop active attacks

What is Identity Threat Detection and Response (ITDR)?

ITDR is the discipline of detecting and responding to active identity-based attacks in real time. Unlike IAM and PAM, which govern who has access, ITDR detects whether that access is being misused right now.

Why it matters

The identity attack surface outgrew your detection model

Identity-based attacks look like normal logins. UEBA, IAM, and traditional ITDR each cover a slice of the problem, and none of them covers the handoffs between the slices.

Hexagon with checkmark icon
Driver 01

Human-centric detection

A growing share of the identities on your network aren't people. They're service accounts, AI agents, and OAuth apps, and ITDR tools built around human behavior largely can't see them.

Cloud icon
Driver 02

Credential theft beats exploitation

Attackers log in. With stolen credentials, abused OAuth connections, or unrevoked service account tokens, they move through cloud, SaaS, and AI using the same pathways as legitimate users.

Warning triangle icon
Driver 03

Anomalies without context

UEBA surfaces behavioral flags. Without cross-domain correlation, it can't tell you what the attacker touched next, how far they moved, or whether the access was legitimate or malicious.

Coverage

Every identity in the environment, human and non-human

Mitiga monitors every identity in your environment, including the ones that run under service credentials instead of a person.

01

Employees, contractors, admins, and federated or SSO users

04

Service accounts and machine identities

02

OAuth apps and API tokens

05

AI agents, copilots, and embedded chatbots

03

Federated access across Okta, Entra ID, Ping Identity, and AWS IAM

06

SaaS platform identities in Salesforce, GitHub, Snowflake, Microsoft 365, Workday, and elsewhere

Agentic Runtime Security

Mitiga detects identity compromise from first signal to full containment

Identity threats go undetected because no single tool has the context to read the signals. Mitiga watches every identity type, correlates activity across platforms, and reconstructs the full attack path so your team can contain threats before they become breaches.

Continuous Behavioral Baselining

Mitiga baselines every identity across authentication, data access, and permission use, and keeps that fingerprint current. Deviations like impossible travel, token misuse, or activity on a long-dormant account surface with the related activity already attached.

Non-Human Identity (NHI) Coverage

Service accounts, AI agents, OAuth apps, and API tokens operate entirely outside the view of tools built for people. Mitiga extends behavioral detection to every non-human identity, including ChatGPT Enterprise, Copilot, Agentforce, Bedrock, Vertex, and Azure AI.

Behavioral Detection and AI Triage

Mitiga evaluates impossible travel, token misuse, abnormal permission changes, and atypical admin actions across platforms, and separates active abuse from benign behavior. Every alert arrives with a structured analysis and a verdict attached.

Cross-Domain Correlation

Identity compromise seldom stops at identity. Mitiga connects identity signals to cloud, SaaS, and AI activity and traces lateral movement from the first hop out to the full blast radius. A compromised Okta user, an abused OAuth token, and an AI agent reaching data it has never touched get assembled into one incident rather than three separate alerts.

Attack Timeline Reconstruction

Mitiga reconstructs a single chronological timeline from full-fidelity forensic data across identity, SaaS, cloud, and AI, retained for 1,000+ days. That is the record an investigation runs on and the evidence a breach disclosure has to show.

Shadow Identity Discovery

Shadow service accounts, undocumented OAuth integrations, unrevoked tokens, and unsanctioned AI connections accumulate without review. Mitiga surfaces them continuously, so the exposure is documented and owned before someone uses it.

Objectives

Operational control over active identity compromise

Hexagon with checkmark icon
Driver 01

Human-centric detection

A growing share of the identities on your network aren't people. They're service accounts, AI agents, and OAuth apps, and ITDR tools built around human behavior largely can't see them.

Cloud icon
Driver 02

Credential theft beats exploitation

Attackers log in. With stolen credentials, abused OAuth connections, or unrevoked service account tokens, they move through cloud, SaaS, and AI using the same pathways as legitimate users.

Warning triangle icon
Driver 03

Anomalies without context

UEBA surfaces behavioral flags. Without cross-domain correlation, it can't tell you what the attacker touched next, how far they moved, or whether the access was legitimate or malicious.

Zero-Impact Breach Prevention.

Let them come.

Why other approaches fall short

Posture tells you the door was unlocked. ITDR tells you who walked through it.

IAM and PAM govern who has access. They have no mechanism for detecting whether that access is being abused in real time. Traditional ITDR tools were built before non-human identities existed at scale. They can't baseline an AI agent, monitor OAuth behavioral patterns, or correlate a service account's activity across cloud and SaaS. As NHI grows as a share of enterprise identity, the coverage gap in a human-centric model widens with it.

Posture and prevention tools find misconfigured permissions and overprivileged accounts. They stop working at the moment of compromise. Once a valid token is in play, the exposure is no longer a posture problem. UEBA surfaces behavioral anomalies, but a single alert from Okta carries almost no meaning on its own. The signal only resolves when correlated with what that identity did in AWS, Salesforce, or an AI service in the following ten minutes. Without cross-domain context, anomaly detection produces volume without verdict.

Verdicts come from behavioral context and cross-domain correlation across every identity, human or not.

FAQ

Frequently asked questions

What is Identity Threat Detection and Response (ITDR)?

+

ITDR is the discipline of detecting and responding to active identity-based attacks in real time. Unlike IAM and PAM, which govern who has access, ITDR detects whether that access is being misused right now.

How is Mitiga's ITDR different from traditional UEBA?

+

UEBA surfaces individual behavioral anomalies, but a single alert has almost no meaning without cross-domain correlation. Mitiga connects identity signals to what happened next in cloud, SaaS, and AI, so every alert arrives with a structured analysis and a verdict, not just a flag.

What is a non-human identity threat?

+

A non-human identity threat is compromise or misuse of an identity that isn't a person, such as a service account, OAuth app, or AI agent. These identities are a growing share of every environment, and most tools built around human behavior can't see them.

Does Mitiga cover AI agent and copilot identities?

+

Yes. Mitiga extends behavioral detection to AI agents, copilots, and embedded chatbots, including ChatGPT Enterprise, Copilot, Agentforce, Bedrock, Vertex, and Azure AI.

How does Mitiga's ITDR integrate with existing identity providers?

+

Mitiga monitors federated access across Okta, Entra ID, Ping Identity, and AWS IAM, alongside SaaS platform identities in Salesforce, GitHub, Snowflake, Microsoft 365, Workday, and elsewhere.

How long is identity activity retained?

+

Identity activity is retained for 1,000+ days as part of the Cloud Security Data Lake, giving investigations and breach disclosures a forensic-grade record to work from.

How does ITDR relate to the Cloud Security Data Lake?

+

ITDR runs on the same Cloud Security Data Lake that powers Mitiga's other detection capabilities. Identity signals are normalized and retained alongside cloud, SaaS, and AI activity, so correlation across domains happens in one connected timeline rather than in separate silos.

Don't miss these stories

Zero-Impact Breach Prevention

Stop identity attacks before they become breaches

From the first anomalous signal, Mitiga's ITDR follows an attack across Okta, Entra ID, a shadow service account, or an AI agent acting outside its baseline, to full cross-domain blast radius and contained incident. It gives you the detection speed and forensic depth to stop attackers before they move from identity into data.

Let them come.