Identity threat detection and response
The credential is the perimeter. Guardian defends it in real time.
Eight out of ten intrusions Guardian Labs investigated last year involved a valid credential rather than malware. Sentinel ITDR watches every authentication, every privilege change and every token exchange across Active Directory, Entra ID, Okta, Ping and your cloud providers — then revokes the session before the adversary reaches anything that matters.
The problem
Your IdP tells you a login succeeded. It cannot tell you it was theft.
Identity providers are built to grant access, not to question it. They log the authentication, apply the conditional access policy and move on. What they do not see is the LSASS read that produced the hash three minutes earlier, the unsigned binary that replayed the refresh token, or the fact that this service account has never once touched a domain controller in four years of telemetry.
Sentinel joins directory events to endpoint, network and cloud telemetry in a single behavioural graph. When a credential is used, the platform already knows how it was obtained, from which process, on which device, and whether that combination has ever been legitimate in your environment.
Credential theft
LSASS access, DPAPI abuse, browser cookie extraction, SAM hive dumps and KRBTGT interaction — caught at the process, not inferred from the login.
MFA circumvention
Push bombing, adversary-in-the-middle proxies, SIM-swap indicators, device code phishing and legacy protocol fallbacks that quietly bypass policy.
Privilege abuse
Shadow admin discovery, nested group escalation, DCSync, ACL backdoors and role assignments that grant far more than the ticket described.
Lateral movement
Pass-the-hash, pass-the-ticket, overpass-the-hash, remote service creation and WMI execution correlated to the identity that authorised them.
Attack path analysis
See the route to domain admin before an adversary walks it
Sentinel continuously computes the shortest privilege escalation paths between every identity and every Tier-0 asset you own, on-premises and in cloud. Paths are ranked by how easily they are traversed, not by how many objects they contain — a three-hop path guarded by phishing-resistant MFA scores lower than a two-hop path through an unmonitored service account.
Scroll horizontally to see the full graph on a small screen.
Every edge, not just group membership
Sentinel resolves ACL write rights, GPO links, delegated OU control, certificate template misconfigurations, SPN ownership, laps read rights and cross-forest trusts — 41 edge types on-premises and 26 in cloud directories.
Ranked by traversal cost
Each edge carries a cost derived from required privilege, tooling maturity, detection coverage and MFA strength. Fixing the single highest-value edge typically removes 60–80% of paths to Tier 0 in a first assessment.
Remediation you can actually ship
Every path ships with the exact change that breaks it — the group to unnest, the ACE to remove, the template to re-permission — plus a simulated before/after blast radius so change control has a number to approve.
Detection coverage
312 identity detections, written and maintained by Guardian Labs
Coverage is published, versioned and tested against live adversary tooling every release. Each detection carries its ATT&CK mapping, expected false-positive profile and the telemetry it requires, so you know exactly what you are buying.
| Technique | ATT&CK ID | Signal source | Median detection latency | Precision | Default response |
|---|---|---|---|---|---|
| Kerberoasting | T1558.003 | Domain sensor · ticket encryption downgrade | 2.1 s | 98.4% | Alert & force credential rotation |
| AS-REP roasting | T1558.004 | Domain sensor · pre-auth disabled accounts | 1.8 s | 99.1% | Alert & re-enable pre-authentication |
| Golden ticket forgery | T1558.001 | Domain sensor · anomalous TGT lifetime and RID | 3.4 s | 99.6% | Isolate host & reset KRBTGT twice |
| Pass-the-hash | T1550.002 | Endpoint sensor · NTLM logon without interactive session | 0.9 s | 97.2% | Kill session & isolate host |
| DCSync | T1003.006 | Domain sensor · replication request from non-DC | 1.2 s | 99.8% | Block, disable principal, page on-call |
| Adversary-in-the-middle session theft | T1557.003 | IdP logs · token binding and TLS fingerprint mismatch | 1.4 s | 96.7% | Revoke refresh tokens & require re-auth |
| MFA push fatigue | T1621 | IdP logs · denial burst then approval | 4.0 s | 94.3% | Suspend factor & notify user out of band |
| OAuth consent phishing | T1528 | Cloud directory · new app grant with mail scopes | 6.2 s | 95.8% | Revoke grant & quarantine application |
| Shadow admin creation | T1098 | Directory graph · new edge to Tier-0 object | 11 s | 99.0% | Revert ACE & open change review |
| Certificate template abuse (ESC1–ESC8) | T1649 | ADCS sensor · enrolment with alternate SAN | 2.6 s | 98.9% | Revoke certificate & disable template |
Scroll horizontally to see all columns.
Full coverage matrix, including the 302 detections not listed here, ships in the product and is mirrored in the identity datasheet.
MFA and SSO integration
Sentinel becomes the risk signal your identity provider was missing
Rather than replacing conditional access, Sentinel feeds it. Continuous risk scores are published back to the IdP through native risk APIs, so your existing policies can step up, block or revoke without a single new policy engine to operate.
Scroll horizontally to see the full diagram on a small screen.
Native, bidirectional, and boring to operate
Connectors are read/write and use the vendor's supported risk and lifecycle APIs. There is no inline proxy, no SAML man-in-the-middle, and no change to your authentication flow — which means no new single point of failure in front of every login.
- Microsoft Entra ID — risky user and risky sign-in publication, continuous access evaluation, token revocation, role removal, and Conditional Access named-location enrichment.
- Okta — Risk Events API ingestion and publication, session clear, factor reset, group removal and Universal Directory attribute writes.
- Ping Identity — PingOne risk predictor feed, PingFederate session termination and adaptive authentication policy triggers.
- Active Directory — account disable, Kerberos ticket purge, password reset with forced change, and protected-group removal via a hardened response service.
- Privileged access managers — CyberArk, BeyondTrust and Delinea session termination plus just-in-time checkout revocation.
Privilege abuse detection
Privilege is only dangerous when it is used unexpectedly
Static entitlement reviews tell you who could do something. Sentinel tells you who did, when, from where, and whether it fits four weeks of their own behaviour. This is the difference between an access certification campaign and a detection.
Tiering that reflects reality
Sentinel derives effective privilege rather than reading a label. An account
in no privileged group but holding GenericAll over an OU containing domain admins is
treated as Tier 0, because it is.
Representative distribution from a 12,000-seat manufacturing tenant. Shadow admins were discovered in the first four hours of deployment.
A privilege escalation, minute by minute
-
09:14:02 · T+0
Helpdesk account authenticates from a new device
A Tier-2 helpdesk identity signs in successfully with a push approval from a device registered eleven minutes earlier. Risk score moves from 12 to 41; the session is allowed but marked for elevated scrutiny.
-
09:16:38 · T+2m 36s
Enumeration of privileged group membership
LDAP queries enumerate members of Domain Admins, Enterprise Admins and three custom Tier-0 groups within nine seconds — a pattern this identity has never produced. Risk score 63.
-
09:18:11 · T+4m 09s
Write to an ACL on a Tier-0 organisational unit
The account adds itself an ACE granting
WriteDaclover the Servers OU. Sentinel classifies this as shadow admin creation, T1098, and the risk score jumps to 91. -
09:18:12 · T+4m 10s
Autonomous containment
Tokens revoked, account disabled, Kerberos tickets purged across the forest, the ACE reverted from the last known-good snapshot, and the originating device isolated. Total elapsed time from the first anomalous LDAP query: 94 seconds.
-
09:19:40 · T+5m 38s
Analyst receives a finished case
The incident arrives with the full path graph, the four objects touched, the reverted change diff, the evidence bundle and a one-paragraph narrative — not 340 raw directory events.
Non-human identity risk
Service accounts outnumber your people 46 to one and nobody owns them
They cannot be enrolled in MFA, their passwords are frequently older than the engineers who set them, and their permissions accreted over a decade of tickets. Sentinel treats every non-human identity as a first-class monitored principal with its own behavioural baseline.
Scroll horizontally to see the full chart on a small screen.
Discovery
Day oneSentinel identifies non-human identities by behaviour, not naming convention: interactive logon absence, constant request cadence, single-source-IP patterns and absent MFA enrolment. Typical first scan surfaces 30–40% more service accounts than the CMDB holds.
Ownership
ContinuousEach identity is attributed to a probable owning team using authentication source, target systems, change history and ticket references. Unclaimed accounts are queued for attestation with a supporting evidence pack rather than a bare list.
Right-sizing
GuidedEffective permissions are compared against 90 days of actual use to generate a least-privilege policy you can apply as a change, along with the exact operations that would have been denied had it been in force.
| Risk factor | Weight | Why it matters |
|---|---|---|
| Tier-0 reachability | 30 | The identity holds, or can obtain within two hops, control over a domain controller, PKI issuer or cloud tenant root. |
| Credential age and type | 20 | Static password older than 365 days, no managed service account, or a long-lived secret where a workload identity federation is available. |
| Interactive logon capability | 15 | The account can log on interactively or via RDP, meaning a human can borrow it and leave no distinguishing trace. |
| Permission-to-use gap | 15 | Effective permissions materially exceed the operations actually observed over 90 days. |
| Exposure surface | 10 | Credential appears in a repository, pipeline variable, scheduled task, GPO preference or configuration file discovered by the endpoint sensor. |
| Behavioural volatility | 10 | Authentication sources, target hosts or request volumes deviate from the account's own established baseline. |
Scroll horizontally to see all columns.
Response
Four actions that end an identity attack
Every action is reversible, fully audited, and available manually, on approval, or autonomously depending on the response tier you configure for that identity class.
-
Revoke
All refresh and access tokens invalidated through continuous access evaluation, Kerberos tickets purged forest-wide, and active application sessions terminated. Effective in under two seconds on Entra ID and Okta.
-
Contain
The account is disabled or moved to a quarantine policy, group memberships that grant Tier-0 reach are removed, and the originating device is network-isolated with the Guardian endpoint sensor still reachable.
-
Rotate
Passwords, certificates, client secrets and API keys tied to the compromised principal are rotated through your secret manager, with dependent services identified in advance so rotation does not become an outage.
-
Restore
Directory objects modified during the intrusion are diffed against the last known-good snapshot and reverted selectively. The full change history stays available as evidence for the investigation and any regulatory filing.
Identity response does not have to be all or nothing
Configure autonomy per identity tier: full automation for standard users, approval-gated actions for Tier-1 admins, and human-only response for break-glass accounts. Response policy is expressed as code, versioned, and testable in a dry-run mode that reports what would have happened without touching production.
We had run three separate Active Directory hardening projects and still could not answer a simple board question: how many steps from a laptop to domain admin? Guardian answered it in four hours, and then showed us the eleven changes that made the number go up.
What changes in the first 90 days
Numbers are medians across 40 enterprise deployments completed in 2025. Every deployment begins with a read-only assessment; nothing is enforced until you decide it should be.
Questions
What identity teams ask us first
Do we have to install anything on our domain controllers?
A lightweight read-only sensor runs on each domain controller or, if you prefer, on a member server receiving a replicated event stream. It consumes under 1% CPU at steady state, requires no schema extension, and never writes to the directory unless you explicitly enable a response action.
For Entra ID, Okta and Ping, integration is API-only — no software is deployed at all.
How is this different from our PAM solution?
Privileged access management brokers and records privileged sessions you route through it. ITDR watches everything, including the privilege paths that bypass the broker entirely — which is exactly where attackers operate. The two are complementary: Sentinel integrates with CyberArk, BeyondTrust and Delinea to terminate brokered sessions and revoke just-in-time checkouts when risk crosses your threshold.
Will automated response lock out legitimate users?
Automated response is opt-in per detection and per identity tier, and every policy can run in dry-run mode first. In dry run, Sentinel reports exactly which accounts would have been actioned over the last 30 days so you can tune before enforcing. Across the customer base, autonomous identity actions carry a 0.3% reversal rate, and every action is a single click to undo with full audit trail.
Which directories and identity providers are supported?
Active Directory Domain Services, Active Directory Certificate Services, Active Directory Federation Services, Microsoft Entra ID, Okta, Ping Identity, JumpCloud, Google Cloud Identity, AWS IAM and IAM Identity Center, Google Cloud IAM, Azure RBAC, and any SCIM 2.0 or OpenID Connect provider through the generic connector.
See the full list on the integrations page.
How much directory data leaves our environment?
Object metadata, relationship edges and authentication events are processed in your chosen region. Password hashes, secrets and certificate private keys are never read, transmitted or stored. Sensitive attribute values can be hashed at the sensor before they leave the host. Details are documented in Trust and security.
Can we run identity detections against historical data?
Yes. Every new or updated detection is automatically replayed against your retained telemetry — 90 days by default, up to seven years on the Enterprise plan — so a technique published today surfaces the intrusion that used it last quarter. Retroactive hits open as normal cases with their original timestamps preserved.
Keep going
Identity is one surface. Sentinel covers the rest the same way.
Endpoint security
Where credentials are stolen in the first place. Process-level prevention with one-click rollback.
Cloud security
Entitlement analysis for AWS, Azure and Google Cloud, correlated to the same identity graph.
Data protection
What the stolen identity was reaching for, and how Sentinel stops it leaving.
Threat intelligence
Which adversaries are running these identity techniques against your industry right now.
Find out how many hops you are from domain admin
A Guardian identity assessment connects read-only to one directory and returns a ranked attack path report, a shadow admin inventory and a non-human identity census. It takes four hours and costs nothing.