Identity threat detection and response

The credential is the perimeter. Guardian defends it in real time.

Eight out of ten intrusions Guardian Labs investigated last year involved a valid credential rather than malware. Sentinel ITDR watches every authentication, every privilege change and every token exchange across Active Directory, Entra ID, Okta, Ping and your cloud providers — then revokes the session before the adversary reaches anything that matters.

1.4s Median time from malicious authentication to enforced session revocation
79% Of confirmed intrusions in 2025 used valid credentials, not malware
46:1 Median ratio of non-human to human identities in enterprise tenants
312 Identity-specific detections mapped to MITRE ATT&CK techniques
0 Directory schema changes required to deploy the domain sensor

The problem

Your IdP tells you a login succeeded. It cannot tell you it was theft.

Identity providers are built to grant access, not to question it. They log the authentication, apply the conditional access policy and move on. What they do not see is the LSASS read that produced the hash three minutes earlier, the unsigned binary that replayed the refresh token, or the fact that this service account has never once touched a domain controller in four years of telemetry.

Sentinel joins directory events to endpoint, network and cloud telemetry in a single behavioural graph. When a credential is used, the platform already knows how it was obtained, from which process, on which device, and whether that combination has ever been legitimate in your environment.

Credential theft

LSASS access, DPAPI abuse, browser cookie extraction, SAM hive dumps and KRBTGT interaction — caught at the process, not inferred from the login.

MFA circumvention

Push bombing, adversary-in-the-middle proxies, SIM-swap indicators, device code phishing and legacy protocol fallbacks that quietly bypass policy.

Privilege abuse

Shadow admin discovery, nested group escalation, DCSync, ACL backdoors and role assignments that grant far more than the ticket described.

Lateral movement

Pass-the-hash, pass-the-ticket, overpass-the-hash, remote service creation and WMI execution correlated to the identity that authorised them.

Attack path analysis

See the route to domain admin before an adversary walks it

Sentinel continuously computes the shortest privilege escalation paths between every identity and every Tier-0 asset you own, on-premises and in cloud. Paths are ranked by how easily they are traversed, not by how many objects they contain — a three-hop path guarded by phishing-resistant MFA scores lower than a two-hop path through an unmonitored service account.

ON-PREMISES ACTIVE DIRECTORY CLOUD IDENTITY — ENTRA ID TENANT j.reyes Standard user · Finance Session token stolen WKS-4471 Managed laptop · Windows 11 LSASS handle opened svc_sqlbackup Non-human · no MFA possible Password age: 1,340 days Backup Operators Tier-0 group · nested x3 SeBackupPrivilege DC01.corp.local Domain controller · Tier 0 DCSync → full NTDS Refresh token replay Unfamiliar ASN · 1,900 km Device not compliant Global Administrator Directory role assignment Tenant-wide authority AiTM proxy T1557.003 OS credential T1003.001 nested membership T1078.002 T1003.006 T1550.001 Sentinel severed the path at hop 3 Service account disabled, Kerberos tickets purged, blast radius reduced from 4,118 objects to 12. Compromised Tier-0 objective Observed technique Automated containment point

Scroll horizontally to see the full graph on a small screen.

Reconstructed from an anonymised Guardian incident. The graph is recomputed every 15 minutes and on every privilege-changing directory event.

Every edge, not just group membership

Sentinel resolves ACL write rights, GPO links, delegated OU control, certificate template misconfigurations, SPN ownership, laps read rights and cross-forest trusts — 41 edge types on-premises and 26 in cloud directories.

Ranked by traversal cost

Each edge carries a cost derived from required privilege, tooling maturity, detection coverage and MFA strength. Fixing the single highest-value edge typically removes 60–80% of paths to Tier 0 in a first assessment.

Remediation you can actually ship

Every path ships with the exact change that breaks it — the group to unnest, the ACE to remove, the template to re-permission — plus a simulated before/after blast radius so change control has a number to approve.

Detection coverage

312 identity detections, written and maintained by Guardian Labs

Coverage is published, versioned and tested against live adversary tooling every release. Each detection carries its ATT&CK mapping, expected false-positive profile and the telemetry it requires, so you know exactly what you are buying.

Selected detections from the identity library, release 2026.7. Confidence reflects median precision measured across the Guardian customer base over the trailing 90 days.
Technique ATT&CK ID Signal source Median detection latency Precision Default response
Kerberoasting T1558.003 Domain sensor · ticket encryption downgrade 2.1 s 98.4% Alert & force credential rotation
AS-REP roasting T1558.004 Domain sensor · pre-auth disabled accounts 1.8 s 99.1% Alert & re-enable pre-authentication
Golden ticket forgery T1558.001 Domain sensor · anomalous TGT lifetime and RID 3.4 s 99.6% Isolate host & reset KRBTGT twice
Pass-the-hash T1550.002 Endpoint sensor · NTLM logon without interactive session 0.9 s 97.2% Kill session & isolate host
DCSync T1003.006 Domain sensor · replication request from non-DC 1.2 s 99.8% Block, disable principal, page on-call
Adversary-in-the-middle session theft T1557.003 IdP logs · token binding and TLS fingerprint mismatch 1.4 s 96.7% Revoke refresh tokens & require re-auth
MFA push fatigue T1621 IdP logs · denial burst then approval 4.0 s 94.3% Suspend factor & notify user out of band
OAuth consent phishing T1528 Cloud directory · new app grant with mail scopes 6.2 s 95.8% Revoke grant & quarantine application
Shadow admin creation T1098 Directory graph · new edge to Tier-0 object 11 s 99.0% Revert ACE & open change review
Certificate template abuse (ESC1–ESC8) T1649 ADCS sensor · enrolment with alternate SAN 2.6 s 98.9% Revoke certificate & disable template

Scroll horizontally to see all columns.

Full coverage matrix, including the 302 detections not listed here, ships in the product and is mirrored in the identity datasheet.

MFA and SSO integration

Sentinel becomes the risk signal your identity provider was missing

Rather than replacing conditional access, Sentinel feeds it. Continuous risk scores are published back to the IdP through native risk APIs, so your existing policies can step up, block or revoke without a single new policy engine to operate.

SIGNALS RISK ENGINE DECISION ENFORCEMENT Endpoint posture and process lineage Network path, ASN and geo-velocity Directory and privilege changes Cloud entitlement drift Guardian Labs threat intelligence 30-day behavioural baseline per identity agent telemetry · 40 ms flow records · 120 ms domain sensor · 300 ms provider APIs · 60 s streamed · continuous recomputed hourly Sentinel risk engine graph + behavioural model 78 / 100 current risk recalculated on every event p95 end to end: 340 ms 0–29 · Allow no user friction, log only 30–59 · Step up FIDO2 or passkey required 60–84 · Restrict read-only, no download, no OAuth 85–100 · Revoke kill tokens, disable, page SOC Your IdP Entra ID Okta Ping Identity Active Directory CyberArk Risk is continuous, not a login-time snapshot — a session that turns hostile after authentication is downgraded mid-flight.

Scroll horizontally to see the full diagram on a small screen.

Native, bidirectional, and boring to operate

Connectors are read/write and use the vendor's supported risk and lifecycle APIs. There is no inline proxy, no SAML man-in-the-middle, and no change to your authentication flow — which means no new single point of failure in front of every login.

  • Microsoft Entra ID — risky user and risky sign-in publication, continuous access evaluation, token revocation, role removal, and Conditional Access named-location enrichment.
  • Okta — Risk Events API ingestion and publication, session clear, factor reset, group removal and Universal Directory attribute writes.
  • Ping Identity — PingOne risk predictor feed, PingFederate session termination and adaptive authentication policy triggers.
  • Active Directory — account disable, Kerberos ticket purge, password reset with forced change, and protected-group removal via a hardened response service.
  • Privileged access managers — CyberArk, BeyondTrust and Delinea session termination plus just-in-time checkout revocation.

See all identity connectors

Phishing-resistant by default Sentinel reports which identities can still satisfy MFA with a phishable factor, ranked by the privilege they hold. Most customers find their highest-privilege accounts are also their least protected.
Legacy authentication still exists The platform flags every successful basic-auth, IMAP, SMTP AUTH and device-code grant against a privileged identity, with the exact application and client string responsible.
Break-glass accounts respected Designated emergency accounts are excluded from automated response and monitored with a separate, higher-sensitivity ruleset that pages a human on any use.

Privilege abuse detection

Privilege is only dangerous when it is used unexpectedly

Static entitlement reviews tell you who could do something. Sentinel tells you who did, when, from where, and whether it fits four weeks of their own behaviour. This is the difference between an access certification campaign and a detection.

Tiering that reflects reality

Sentinel derives effective privilege rather than reading a label. An account in no privileged group but holding GenericAll over an OU containing domain admins is treated as Tier 0, because it is.

Tier 0 — directory control 214 identities
Tier 1 — server and application admin 1,846 identities
Tier 2 — workstation and helpdesk 4,209 identities
Shadow admins — undeclared Tier 0 63 identities

Representative distribution from a 12,000-seat manufacturing tenant. Shadow admins were discovered in the first four hours of deployment.

A privilege escalation, minute by minute

  1. 09:14:02 · T+0

    Helpdesk account authenticates from a new device

    A Tier-2 helpdesk identity signs in successfully with a push approval from a device registered eleven minutes earlier. Risk score moves from 12 to 41; the session is allowed but marked for elevated scrutiny.

  2. 09:16:38 · T+2m 36s

    Enumeration of privileged group membership

    LDAP queries enumerate members of Domain Admins, Enterprise Admins and three custom Tier-0 groups within nine seconds — a pattern this identity has never produced. Risk score 63.

  3. 09:18:11 · T+4m 09s

    Write to an ACL on a Tier-0 organisational unit

    The account adds itself an ACE granting WriteDacl over the Servers OU. Sentinel classifies this as shadow admin creation, T1098, and the risk score jumps to 91.

  4. 09:18:12 · T+4m 10s

    Autonomous containment

    Tokens revoked, account disabled, Kerberos tickets purged across the forest, the ACE reverted from the last known-good snapshot, and the originating device isolated. Total elapsed time from the first anomalous LDAP query: 94 seconds.

  5. 09:19:40 · T+5m 38s

    Analyst receives a finished case

    The incident arrives with the full path graph, the four objects touched, the reverted change diff, the evidence bundle and a one-paragraph narrative — not 340 raw directory events.

Non-human identity risk

Service accounts outnumber your people 46 to one and nobody owns them

They cannot be enrolled in MFA, their passwords are frequently older than the engineers who set them, and their permissions accreted over a decade of tickets. Sentinel treats every non-human identity as a first-class monitored principal with its own behavioural baseline.

0 150k 300k 450k 600k 6:1 9:1 14:1 22:1 34:1 46:1 2021 2022 2023 2024 2025 2026 Human identities Non-human identities — service accounts, workload identities, CI/CD tokens, API keys

Scroll horizontally to see the full chart on a small screen.

Discovery

Day one

Sentinel identifies non-human identities by behaviour, not naming convention: interactive logon absence, constant request cadence, single-source-IP patterns and absent MFA enrolment. Typical first scan surfaces 30–40% more service accounts than the CMDB holds.

Ownership

Continuous

Each identity is attributed to a probable owning team using authentication source, target systems, change history and ticket references. Unclaimed accounts are queued for attestation with a supporting evidence pack rather than a bare list.

Right-sizing

Guided

Effective permissions are compared against 90 days of actual use to generate a least-privilege policy you can apply as a change, along with the exact operations that would have been denied had it been in force.

How Sentinel scores non-human identity risk. Factors are additive and capped at 100.
Risk factor Weight Why it matters
Tier-0 reachability 30 The identity holds, or can obtain within two hops, control over a domain controller, PKI issuer or cloud tenant root.
Credential age and type 20 Static password older than 365 days, no managed service account, or a long-lived secret where a workload identity federation is available.
Interactive logon capability 15 The account can log on interactively or via RDP, meaning a human can borrow it and leave no distinguishing trace.
Permission-to-use gap 15 Effective permissions materially exceed the operations actually observed over 90 days.
Exposure surface 10 Credential appears in a repository, pipeline variable, scheduled task, GPO preference or configuration file discovered by the endpoint sensor.
Behavioural volatility 10 Authentication sources, target hosts or request volumes deviate from the account's own established baseline.

Scroll horizontally to see all columns.

Response

Four actions that end an identity attack

Every action is reversible, fully audited, and available manually, on approval, or autonomously depending on the response tier you configure for that identity class.

  1. Revoke

    All refresh and access tokens invalidated through continuous access evaluation, Kerberos tickets purged forest-wide, and active application sessions terminated. Effective in under two seconds on Entra ID and Okta.

  2. Contain

    The account is disabled or moved to a quarantine policy, group memberships that grant Tier-0 reach are removed, and the originating device is network-isolated with the Guardian endpoint sensor still reachable.

  3. Rotate

    Passwords, certificates, client secrets and API keys tied to the compromised principal are rotated through your secret manager, with dependent services identified in advance so rotation does not become an outage.

  4. Restore

    Directory objects modified during the intrusion are diffed against the last known-good snapshot and reverted selectively. The full change history stays available as evidence for the investigation and any regulatory filing.

Identity response does not have to be all or nothing

Configure autonomy per identity tier: full automation for standard users, approval-gated actions for Tier-1 admins, and human-only response for break-glass accounts. Response policy is expressed as code, versioned, and testable in a dry-run mode that reports what would have happened without touching production.

We had run three separate Active Directory hardening projects and still could not answer a simple board question: how many steps from a laptop to domain admin? Guardian answered it in four hours, and then showed us the eleven changes that made the number go up.

Marta Hendricks
Director of Identity and Access, global logistics operator

What changes in the first 90 days

63Shadow admins found and removed
-91%Reduction in paths to Tier 0
4.2kStale non-human identities retired
18 minMedian identity incident closure, down from 6 hours

Numbers are medians across 40 enterprise deployments completed in 2025. Every deployment begins with a read-only assessment; nothing is enforced until you decide it should be.

Questions

What identity teams ask us first

Do we have to install anything on our domain controllers?

A lightweight read-only sensor runs on each domain controller or, if you prefer, on a member server receiving a replicated event stream. It consumes under 1% CPU at steady state, requires no schema extension, and never writes to the directory unless you explicitly enable a response action.

For Entra ID, Okta and Ping, integration is API-only — no software is deployed at all.

How is this different from our PAM solution?

Privileged access management brokers and records privileged sessions you route through it. ITDR watches everything, including the privilege paths that bypass the broker entirely — which is exactly where attackers operate. The two are complementary: Sentinel integrates with CyberArk, BeyondTrust and Delinea to terminate brokered sessions and revoke just-in-time checkouts when risk crosses your threshold.

Will automated response lock out legitimate users?

Automated response is opt-in per detection and per identity tier, and every policy can run in dry-run mode first. In dry run, Sentinel reports exactly which accounts would have been actioned over the last 30 days so you can tune before enforcing. Across the customer base, autonomous identity actions carry a 0.3% reversal rate, and every action is a single click to undo with full audit trail.

Which directories and identity providers are supported?

Active Directory Domain Services, Active Directory Certificate Services, Active Directory Federation Services, Microsoft Entra ID, Okta, Ping Identity, JumpCloud, Google Cloud Identity, AWS IAM and IAM Identity Center, Google Cloud IAM, Azure RBAC, and any SCIM 2.0 or OpenID Connect provider through the generic connector.

See the full list on the integrations page.

How much directory data leaves our environment?

Object metadata, relationship edges and authentication events are processed in your chosen region. Password hashes, secrets and certificate private keys are never read, transmitted or stored. Sensitive attribute values can be hashed at the sensor before they leave the host. Details are documented in Trust and security.

Can we run identity detections against historical data?

Yes. Every new or updated detection is automatically replayed against your retained telemetry — 90 days by default, up to seven years on the Enterprise plan — so a technique published today surfaces the intrusion that used it last quarter. Retroactive hits open as normal cases with their original timestamps preserved.

Find out how many hops you are from domain admin

A Guardian identity assessment connects read-only to one directory and returns a ranked attack path report, a shadow admin inventory and a non-human identity census. It takes four hours and costs nothing.