Skip to main content

ITDR Vendor Landscape

Status: Final

The ITDR market formalized after Gartner coined the term in 2022, but many vendors had been building identity threat detection capabilities for years under different labels (UBA, UEBA, identity security). This page maps the current landscape — what each vendor detects, where their telemetry comes from, and how they position relative to each other.


Market Structure

ITDR vendors come from three origins:

OriginExamplesCore Strength
Security platform vendors (EDR/XDR expanded)Palo Alto Networks, CrowdStrike, MicrosoftCross-domain correlation (endpoint + identity + cloud)
Identity-native vendorsSilverfort, SemperisDeep AD/identity protocol expertise
Cloud identity specialistsPermiso, Push Security, Astrix, VezaCloud identity, SaaS, NHI-focused

Vendor Deep-Dives

Palo Alto Networks — Cortex XDR / Prisma Access ITDR

Market position: Part of the Cortex XDR platform; identity protection integrated into the broader security operations platform.

CapabilityDetail
Identity threat detectionCortex XDR analyzes authentication events, credential access, lateral movement
ITDR moduleDedicated identity analytics on top of XDR telemetry
TelemetryEndpoint (agent), network (NGFW), cloud (Prisma), identity logs
On-prem AD coverageSensor-based collection from DCs + endpoint agents
Cloud coverageEntra ID, Okta, AWS, GCP via API integration
Detection approachML baseline + rule-based detection + threat intelligence
Key differentiatorSingle platform for SOC covering endpoint + network + identity + cloud

Identity-specific capabilities:

  • Credential theft detection (Pass-the-Hash, Kerberoasting, LSASS access)
  • Lateral movement via identity
  • Cloud identity anomalies
  • Workforce/workload identity coverage

Cortex XDR ITDR use cases:

  • Impossible travel detection
  • Token theft and reuse
  • Service account abuse
  • Privilege escalation detection
  • Hybrid attack chain correlation (on-prem → cloud pivot)

CrowdStrike — Falcon Identity Threat Detection (FITD)

Market position: Best-in-class AD identity threat detection; acquired Preempt Security in 2020 to build this capability.

CapabilityDetail
Core strengthReal-time AD authentication stream analysis
Agent-basedFalcon sensor on endpoints + Falcon AD connector on DCs
AD coverageEvery Kerberos and NTLM authentication, in real time
MFA enforcementCan enforce MFA at the authentication layer (even for protocols that don't natively support it)
Conditional access for ADPolicy-based blocking/challenging at the authentication layer
Cloud coverageEntra ID, Okta via API
Key differentiatorSpeed (real-time auth analysis), depth (raw Kerberos/NTLM), MFA enforcement capability

FITD detection examples:

  • Kerberoasting in progress (real-time RC4 ticket storm)
  • Pass-the-Hash (hash-based auth from unexpected source)
  • Lateral movement via PsExec/WMI/DCSync
  • Golden/Silver Ticket anomalies
  • Brute force / password spray
  • Anomalous service account authentication

Microsoft — Microsoft Defender for Identity (MDI) + Entra ID Protection

Market position: Native integration with the Microsoft stack; unmatched depth for Windows AD and Entra ID environments.

ComponentCoverage
Microsoft Defender for Identity (MDI)On-premises AD; sensor on DCs captures Kerberos/NTLM/LDAP traffic
Entra ID Identity ProtectionCloud sign-in risk + user risk scoring
Microsoft SentinelSIEM with identity-focused analytics rules + UEBA
Microsoft Defender XDRCross-domain correlation (identity + endpoint + email + cloud)
Entra ID Conditional AccessEnforcement layer for risk-based access control

MDI key detections:

  • DCSync (Event 4662 pattern)
  • Kerberoasting
  • AS-REP Roasting
  • Pass-the-Hash, Pass-the-Ticket
  • Reconnaissance (LDAP enumeration, DNS enumeration)
  • Lateral movement
  • Domain dominance activities

Advantage: Deepest native Windows AD coverage. No other vendor has access to the same level of Windows internals. Integrates identity risk directly into Conditional Access enforcement.


Silverfort

Market position: Authentication-layer security — sits in-line or near the authentication path to enforce MFA and detect threats at the protocol level.

CapabilityDetail
Core innovationProxy/agentless integration — analyzes authentication traffic without agents on every machine
MFA everywhereEnforce MFA on protocols that don't natively support it: NTLM, Kerberos, LDAP
Service account protectionProfile service account behavior; alert/block anomalies
Lateral movement detectionDetect credential-based lateral movement in real time
Ransomware protectionBlock compromised account from mass authentication (pre-encryption stage)
Non-human identityAutomated discovery and protection of service accounts

Key differentiator: Can enforce MFA on legacy systems and protocols (RDP, file shares via NTLM) without modifying those systems. This is significant for organizations that cannot deploy agents everywhere.


Semperis

Market position: AD-specific security and resilience — AD attack path analysis, forest recovery, and threat detection focused on the AD control plane.

CapabilityDetail
Purple KnightFree AD security assessment tool (attack path analysis, misconfiguration detection)
Directory Services Protector (DSP)Real-time AD change monitoring and rollback
Forest DruidAttack path analysis focused on Tier 0 blast radius
AD security postureContinuous misconfiguration scanning
Attack simulationBloodHound-class path analysis for defenders
Incident responseAD forensics, forest recovery assistance

Key differentiator: Deepest AD-specific expertise. Best for organizations focused on AD security posture and resilience.


Permiso Security

Market position: Cloud identity threat detection — specializes in AWS, Azure, GCP, SaaS identity events.

CapabilityDetail
FocusCloud control plane identity activity (CloudTrail, Entra ID, GCP Audit Logs)
Service principal / managed identityDetects anomalous NHI behavior in cloud
Cloud lateral movementIdentity-based pivoting across cloud services
Entity timelinePer-identity timeline of all cloud activity
Detection libraryPre-built detections for cloud identity attacks

Veza

Market position: Identity authorization graph — "what can every identity do?" across all systems.

CapabilityDetail
Core productAuthorization graph across cloud, SaaS, infrastructure
Non-human identityDiscovers and analyzes service accounts, OAuth apps, API keys
Access intelligenceAnswers "which identities have admin in production?" in real time
IGA integrationFeeds into access certification workflows
Overprivilege detectionFinds identities with more access than their role requires

Astrix Security

Market position: Non-human identity (NHI) and third-party integration security.

CapabilityDetail
OAuth app discoveryDiscovers all OAuth apps connected to corporate M365/Google/Slack
API token inventoryMaps all API keys, service accounts, OAuth tokens
Risk scoringScores NHIs by permissions, last used, owner
OffboardingRevokes NHI access when employees leave

Key use case: Large organizations with hundreds of OAuth apps connected to M365 or Google Workspace — Astrix discovers them and surfaces over-privileged or dormant integrations.


Push Security

Market position: Browser-native identity security for SaaS.

CapabilityDetail
DeliveryChrome extension deployed across the workforce
SaaS discoveryDiscovers all SaaS apps used (shadow IT)
Identity-centricMaps which identities access which SaaS apps
Phishing detectionDetects AiTM phishing via browser-level signals
Credential exposureDetects reused or breached credentials in browser
MFA gapsIdentifies SaaS apps without MFA

Feature Matrix

VendorOn-prem ADEntra ID / CloudSaaS / NHIReal-time blockingMFA enforcement
Palo Alto CortexVia playbooksNo
CrowdStrike FITD✓✓Partial✓ (block auth)✓ (MFA enforcement)
Microsoft MDI + Sentinel✓✓✓✓PartialVia CAVia Entra CA
Silverfort✓✓No✓ (inline)✓✓ (protocol-level)
Semperis DSP✓✓PartialNo✓ (AD rollback)No
PermisoNo✓✓✓✓No (detect only)No
VezaNo✓✓No (posture)No
AstrixNoPartial✓✓ (NHI)NoNo
Push SecurityNoPartial✓✓NoNo

Choosing an ITDR Vendor

If you need…Consider
Deep AD detection + real-time blockingCrowdStrike FITD or Silverfort
Native Microsoft stack integrationMicrosoft MDI + Sentinel
Single platform (endpoint + cloud + identity)Palo Alto Cortex XDR
AD security posture + forest recoverySemperis
Cloud identity anomalies (AWS/Azure/GCP)Permiso
NHI / OAuth app / API key governanceVeza, Astrix
SaaS shadow IT + browser identityPush Security

TopicLink
What is ITDR?what-is-itdr
PAMpam-overview
Detection Frameworkdetection-framework
AD Attackskerberoasting