Stage 01 · The Detector

Catch the collision at the first particle.

ITDR watches every identity event in your environment and registers a compromise the instant it happens — at the smallest level where an attack first becomes visible. The earlier you see it, the smaller it stays.

The detector, reacting: signals scored, triaged, and answered from one control plane — illustrative.
The detector array

Every identity event, read in real time.

Identity is where most modern attacks actually begin. The Detector reads the full signal — not just logins — so a takeover can't hide inside normal-looking activity.

SIG 01

Authentication

Logins, MFA prompts, impossible-travel, and brute-force patterns across every identity provider.

SIG 02

Token & session use

Stolen tokens, replayed sessions, and anomalous OAuth grants that bypass passwords entirely.

SIG 03

Privilege changes

New admin rights, role escalations, and permission grants that quietly widen an attacker's reach.

SIG 04

Account lifecycle

Newly created, dormant, or revived accounts — classic footholds for persistence.

SIG 05

Behavioral drift

Activity that breaks an identity's normal pattern, scored continuously against its own baseline.

SIG 06

Cross-source correlation

The same identity seen across cloud, SaaS, and on-prem — stitched into one timeline.

ContinuousEvery identity event, as it happens

See it, then hand it off.

The moment the Detector registers a compromise, it doesn't just alert — it fires the signal straight into the reaction, so the Containment Field can act before the attacker takes a second step. Detection that leads directly to response, with nothing lost in between.

Where it sits in the reaction
01
Detector
ITDR spots the event, instantly
02
Containment
DomainGuard blocks & filters
03
Observatory
MDR reviews — optional
In the field

Three attacks, caught early.

What detection-to-containment actually looks like when the Detector fires. Timelines are illustrative.

Scenario 01 · Stolen session
  1. 02:14:03Impossible-travel login — Mumbai → Frankfurt in 11 minutes.
  2. 02:14:04Detector scores the session against the identity's baseline — far outside normal.
  3. 02:14:05Token revoked, session killed, client notified.

Outcome: account secured before a second request.

Scenario 02 · Privilege escalation
  1. 09:41A standard user is suddenly granted Global Admin in the tenant.
  2. 09:41Detector flags the role change as anomalous for that account and actor.
  3. 09:42Grant rolled back and the change escalated for review.

Outcome: a quiet foothold closed before it's used.

Scenario 03 · OAuth abuse
  1. 17:08A new OAuth app is consented with broad mailbox scopes.
  2. 17:08Detector correlates the grant with an earlier risky sign-in for the same identity.
  3. 17:09App access revoked; the identity's tokens rotated.

Outcome: token-based persistence cut off at the source.

The platform

One control plane for identity defense.

Premium identity defense for modern MSPs: real-time visibility, automated triage, and a single control plane that turns signals into decisive action — across every tenant you protect.

Capability 01

Continuous identity risk scoring

Every identity carries a live risk score, so triage starts from what's actually most dangerous — not from the newest alert.

Capability 02

Microsoft Graph-powered signals

Sign-ins, tokens, and directory changes read straight from Microsoft Graph — Entra ID and Microsoft 365 telemetry, live.

Capability 03

Unified alert & incident response

Alerts, investigations, and responses live in one queue per tenant — no swivel-chair between a SIEM and a ticket system.

Capability 04

Managed device posture insights

Identity signals enriched with the posture of the managed devices they come from, for cleaner verdicts on risky sessions.

64%alert-noise reduction · platform-reported

Signals become decisions, around the clock.

The platform reports 64% alert-noise reduction and 24/7 unified tenant coverage — so what reaches a human is worth a human. Sign in to monitor risk, respond to incidents, and manage connectors.

Looking for GitHub access reviews? That's Access Review & Evidence — Atomburst's own posture & discovery product, separate from ITDR and self-serve from $15/month.

Questions

ITDR, answered.

How long does deployment take? +
ITDR is cloud-native and connects to your identity sources via API — no agents to roll out for detection. Connect a tenant's Microsoft connectors and signals start flowing; time to first signal is short.
Which identity providers are supported? +
ITDR's signals are powered by Microsoft Graph — Microsoft Entra ID and Microsoft 365 telemetry — enriched with managed-device posture insights. Talk to us about the rest of your identity stack. (GitHub access reviews are a separate Atomburst product: Access Review & Evidence.)
What happens on a false positive? +
Detections are scored against each identity's own baseline to keep noise low. Responses can be tuned per tenant — from notify-only to automatic containment — so a low-confidence event doesn't lock a user out.
How is this different from EDR? +
EDR watches endpoints; ITDR watches identities. Most modern attacks begin with a credential or token, not malware on a laptop — ITDR catches the takeover that never touches the endpoint. They're complementary.
Does it work multi-tenant for MSPs? +
Yes. ITDR is multi-tenant from day one — every client and identity source in one console, with per-tenant policy and detection tuning.
Where does my identity data live, and how long is it kept? +
Event data is encrypted in transit and at rest and retained for a configurable window. See Security & Compliance for specifics.
The promise

The earlier you catch it, the smaller it stays.

See the Detector in action