10 Best ITDR Tools: Complete Identity Threat Detection and Response Guide

10 Best ITDR Tools: Complete Identity Threat Detection and Response Guide (2026)

Quick Summary

The best identity threat detection and response (ITDR) tools are Microsoft Defender for Identity, CrowdStrike Falcon Identity Protection and Silverfort.

ToolBest forStarting priceRating
Microsoft Defender for IdentityTeams running Active Directory and Entra IDIncluded in Microsoft 365 E5 ($60/user/month)4.3/5 (G2)
CrowdStrike Falcon Identity ProtectionTeams already running CrowdStrike Falcon on their endpointsNot published4.6/5 (Gartner Peer Insights)
SilverfortHybrid networks with legacy systems that don’t support multi-factor authentication (MFA)Not published4.7/5 (Gartner Peer Insights)

Why identity attacks get past endpoint and network tools

Verizon’s 2026 Data Breach Investigations Report found credential abuse at some stage of 39% of breaches (p.16). Endpoint and network tools miss most of that abuse. A sign-in with a stolen password looks the same as a sign-in by the employee who owns that password. There’s no malware for EDR (endpoint detection and response) to catch. Attackers get compromised credentials from malware and breach dumps, then test them at scale in credential stuffing attacks.

Why listen to us?

Breachsense doesn’t sell ITDR, so we don’t rank our own product here. Every rating below comes from a public review site. Breachsense is a dark web monitoring API with over 41 billion leaked credentials indexed. Our founder, Josh Amishav, spent nearly 20 years in offensive security, often signing in to client networks with leaked credentials during penetration tests. Our research has been cited by TechTarget and The Register. Lawyers have also cited our breach records in class action lawsuits.

What is ITDR?

ITDR (identity threat detection and response) is a set of security tools and practices for “detecting, investigating, and responding to threats that target digital identities”, in Gartner’s words. An ITDR tool monitors sign-ins and changes to accounts, such as a user added to an admin group. The tool alerts your team about unusual account activity and known attacks, such as one password tried against hundreds of accounts. Some ITDR tools also block suspicious sign-ins or disable compromised accounts.

ITDR tools cover these identity systems and account types:

  • Active Directory. Microsoft’s on-premises directory, where most Windows networks keep their users and admin accounts.
  • Entra ID. Microsoft’s cloud directory for Microsoft 365, formerly called Azure AD.
  • Okta. A cloud identity provider that signs employees in to their work apps.
  • Service accounts. Non-human accounts that applications and scripts use to sign in.

Why is ITDR important?

  • Attackers move between accounts once they’re inside. From the first account, an attacker collects cached credentials (passwords a computer stores after someone signs in). The attacker uses those credentials and Kerberos tickets (the tokens Windows uses to prove who you are) to reach an admin account.
  • Stolen session cookies bypass MFA. An attacker who loads a valid session cookie is already signed in, so there’s no password or MFA prompt to stop them.
  • Service accounts have wide access and little oversight. A service account often has admin rights and a password that rarely changes. No employee signs in with a service account day to day, so nobody notices misuse.
  • Hybrid identity lets attackers cross systems. Many companies sync Active Directory passwords to Entra ID or Okta, so an employee uses the same password on-premises and in the cloud. An attacker who steals that password can sign in on-premises and in the cloud.

Where dark web monitoring fits alongside ITDR

Most ITDR tools catch a stolen password only once someone signs in with it. Dark web monitoring alerts you when the password shows up in a leak, often before anyone has used it. Many of those leaks come from infostealer malware, which copies saved passwords and session cookies from an infected browser into a file called a stealer log.

A password reset alone doesn’t end a stolen session, so revoke the user’s sessions too. Stealer logs we indexed in August 2026 held 422,216 session cookies for Microsoft’s sign-in page, according to our August 2026 infostealer report.

Breachsense sends a webhook alert when your employees’ credentials or session cookies turn up in leaked data. Sources include stealer logs, combo lists (lists of leaked email and password pairs), phishing kits and third-party breaches. Your SOAR tool (the system that runs response steps automatically) can then reset the password and revoke the sessions.

10 best ITDR tools

  1. Microsoft Defender for Identity
  2. CrowdStrike Falcon Identity Protection
  3. Silverfort
  4. SentinelOne Singularity Identity
  5. Huntress Managed ITDR
  6. Semperis Directory Services Protector
  7. Proofpoint Identity Threat Defense
  8. Sophos ITDR
  9. Okta Identity Threat Protection
  10. Bitdefender GravityZone ITDR
ToolBest forStarting priceRating
Microsoft Defender for IdentityTeams running Active Directory and Entra IDIncluded in Microsoft 365 E5 ($60/user/month)4.3/5 (G2)
CrowdStrike Falcon Identity ProtectionTeams already running CrowdStrike Falcon on their endpointsNot published4.6/5 (Gartner Peer Insights)
SilverfortHybrid networks with legacy systems that don’t support MFANot published4.7/5 (Gartner Peer Insights)
SentinelOne Singularity IdentityTeams already on SentinelOne’s endpoint platform$229.99/endpoint/year (Singularity Commercial)4.4/5 (Gartner Peer Insights)
Huntress Managed ITDRSmall businesses and managed service providers (MSPs) without a security team watching alerts$4.80/identity/month (list price)4.8/5 (G2)
Semperis Directory Services ProtectorEnterprises that need to track and roll back Active Directory changesNot published4.8/5 (G2)
Proofpoint Identity Threat DefenseEnterprises that want to remove cached credentials and catch attackers with decoysNot published4.5/5 (Gartner Peer Insights)
Sophos ITDRSophos extended detection and response (XDR) and managed detection and response (MDR) customers on Entra ID and Active DirectoryNot publishedNot enough reviews
Okta Identity Threat ProtectionCompanies that sign employees in through OktaNot publishedNot enough reviews
Bitdefender GravityZone ITDRGravityZone customers who want identity alerts in their XDR consoleNot publishedNot enough reviews

1. Microsoft Defender for Identity

Microsoft Defender for Identity suits security teams whose accounts live in on-premises Active Directory and Entra ID. Microsoft includes Defender for Identity in Microsoft 365 E5 and the Microsoft Defender Suite, so many Microsoft customers already have a license.

Defender for Identity’s sensors run on domain controllers, so Defender for Identity catches attacks on Active Directory itself. Examples are Golden Ticket activity, where an attacker forges a Kerberos ticket that works anywhere in the domain, and DCShadow, where an attacker registers a fake domain controller.

Microsoft Defender for Identity's Identity Security dashboard counting protected human and non-human identities across Entra ID, on-premises Active Directory and SaaS apps. Source: learn.microsoft.com, October 2026.

Key features

  • Active Directory sensors. Runs on domain controllers and on the servers that handle federated sign-in (AD FS), certificates (AD CS) and Entra ID sync (Entra Connect).
  • Shared incidents. Links identity alerts with endpoint and email alerts in the Microsoft Defender portal.
  • Account restriction. Restricts identities confirmed as compromised so an attacker can’t keep using them.
  • Identity posture. Recommends fixes for risky identity settings and shows the attack paths to sensitive accounts.

Pricing: Microsoft doesn’t publish a standalone price. Defender for Identity comes with Microsoft 365 E5 at $60 per user a month, paid yearly. Defender for Identity is also part of the Microsoft Defender Suite, a $12 per user a month add-on to Microsoft 365 E3.

Rating: 4.3/5 on G2

Pros

  • Threat hunting is easier because identity alerts appear in the same Defender portal as endpoint and email alerts.
  • Detects Active Directory attacks such as Pass-the-Hash (signing in with a stolen password hash) and suspicious LDAP queries (directory lookups).
  • Sends alerts to Microsoft Sentinel or another SIEM (the system that collects your security logs) with little setup.

Cons

  • Hard to set up without a good understanding of Active Directory.
  • Produces false positives, especially for cloud activity, until you tune the alerts.
  • Offers few options for writing custom detections or querying raw event data.

2. CrowdStrike Falcon Identity Protection

CrowdStrike Falcon Identity Protection suits teams already running CrowdStrike Falcon on their endpoints, because identity and endpoint detections share one agent and one console. CrowdStrike now sells Falcon Identity Protection as part of Falcon Next-Gen Identity Security.

CrowdStrike Falcon Identity Protection domain security overview with a domain risk score and a list of identity risks, for a demo domain. Source: crowdstrike.com, October 2026.

Key features

  • Hybrid coverage. Protects on-premises Active Directory, Entra ID and Okta identities, plus service accounts.
  • Real-time enforcement. Revokes sessions or requires phishing-resistant MFA when an account’s risk rises, without waiting for an analyst.
  • Lateral movement blocking. Stops an attacker moving from one compromised account or machine to the next.
  • Managed option. CrowdStrike also sells a 24/7 service where CrowdStrike analysts investigate identity alerts for you.

Pricing: Not published. CrowdStrike licenses Falcon Next-Gen Identity Security per active identity, meaning each account that signed in during the last 90 days, including service accounts. CrowdStrike offers a 15-day free trial that includes all Falcon Next-Gen Identity Security capabilities.

Rating: 4.6/5 on Gartner Peer Insights

Pros

  • Teams already on Falcon have no new server or agent to install.
  • Flags accounts with compromised passwords, and accounts that share a password.
  • Shows what service accounts are doing in real time.

Cons

  • The price is hard to justify, especially for a small business.
  • Dashboards and response actions are hard to customize, and you can’t run a response action on several identities at once.
  • Alerts are noisy out of the box, until you tune the detection rules.

3. Silverfort

Silverfort suits hybrid networks with legacy systems and service accounts that don’t support MFA. Silverfort enforces MFA and access policies inside the sign-in flow, so Active Directory and your cloud apps need no changes.

Silverfort ITDR incidents table listing password spray, brute force and MFA bypass incidents with severity, status and attack tactic. Source: silverfort.com, October 2026.

Key features

  • Inline blocking. Blocks a sign-in or requires MFA before the sign-in completes. Silverfort can also end a session.
  • Active Directory attack detection. Detects Pass-the-Hash, Pass-the-Ticket, Kerberoasting and DCSync, techniques attackers use to reuse or steal Active Directory credentials.
  • Service account protection. Discovers, classifies and locks down Active Directory service accounts.
  • Integrations. Sends detections to your SIEM or XDR tool. Silverfort can also send detections to a SOAR tool.

Pricing: Not published. Silverfort prices by organization size, and ITDR starts in its Advanced package. Silverfort offers a self-guided product tour but no free trial.

Rating: 4.7/5 on Gartner Peer Insights

Pros

  • Adds MFA to legacy systems without major changes to your existing infrastructure.
  • Behavior monitoring catches unusual account activity quickly.

Cons

  • Setup gets complex when you connect legacy systems or several existing tools.
  • Admins need time to tune authentication rules, or users get unneeded MFA prompts.
  • The dashboard takes time to get used to.

4. SentinelOne Singularity Identity

SentinelOne Singularity Identity suits teams on SentinelOne’s endpoint platform, because Singularity Identity runs on the same agent and console. Singularity Identity protects Active Directory and cloud identity providers, including Entra ID, Okta, Ping, SecureAuth and Duo.

SentinelOne Singularity Identity misconfigurations console listing Active Directory findings such as accounts with never-expiring passwords and Kerberos delegation on privileged accounts. Source: sentinelone.com, October 2026.

Key features

  • Lateral movement blocking. Blocks lateral movement across endpoints and domains in real time.
  • Decoy identities. Plants decoy accounts, so an attacker who tries a decoy while mapping your network sets off an alert.
  • Conditional access. Requires MFA again or blocks the session when SentinelOne detects an identity attack. SentinelOne uses conditional access rules for both actions. Conditional access rules decide whether a sign-in needs MFA or gets blocked.
  • Leaked credential alerts. Flags stolen or compromised credentials exposed on the dark web.

Pricing: SentinelOne publishes one price that includes identity detection. Singularity Commercial costs $229.99 per endpoint a year for 5 to 100 workstations, bought through a SentinelOne partner. Enterprise pricing isn’t published. SentinelOne offers a demo and a product tour but no free trial.

Rating: 4.4/5 on Gartner Peer Insights

Pros

  • Easy to deploy for teams already on SentinelOne.
  • Shows the paths an attacker could take to pivot into an endpoint.
  • Highlights identity misconfigurations, such as risky settings on privileged accounts.

Cons

  • Behavioral detection often flags legitimate admin scripts as threats.
  • The price is steep, and getting every capability takes several modules.
  • Some response features are still on SentinelOne’s roadmap rather than in the product.

5. Huntress Managed ITDR

Huntress Managed ITDR suits small and mid-sized businesses without their own security team, and the MSPs that serve them.

Huntress detection covers Microsoft 365 and Google Workspace accounts. In on-premises Active Directory, Huntress can only disable accounts that sync to Entra ID, through an agent on the domain controller.

Huntress Managed ITDR dashboard showing open identity incidents, Rapid Identity Triage and sign-in locations, with user names blurred. Source: huntress.com, October 2026.

Key features

  • 24/7 managed response. Huntress analysts investigate alerts and disable compromised accounts.
  • Session hijacking detection. Catches attackers who use a stolen session to bypass MFA.
  • Rogue app and inbox rule detection. Finds rogue apps that users granted access to their Microsoft 365 or Google account, and malicious inbox forwarding rules.
  • Account response. Revokes active sessions or disables an account from the Huntress dashboard.

Pricing: Huntress publishes a list price of $4.80 per identity a month, on a 12-month subscription billed annually. The rate drops with volume. Huntress’s pricing example shows $3.60 per identity for 100 identities. MSPs get partner pricing. Huntress offers a free trial with no credit card required.

Rating: 4.8/5 on G2

Pros

  • Setup takes minutes. You approve access with a Microsoft 365 global admin account.
  • Your team doesn’t triage the identity alerts, because Huntress analysts handle the alerts and disable compromised accounts.
  • Each alert includes a plain-language summary of the threat and next steps a junior technician can follow.

Cons

  • Huntress manages the detection rules, so you can’t write your own.
  • You can’t export the incident timeline, so you build incident reports by hand.
  • MSP partners face a 50-license minimum, which is pricey for a new MSP.

6. Semperis Directory Services Protector

Semperis Directory Services Protector (DSP) suits enterprises that run Entra ID alongside complex Active Directory setups, including several forests (separate Active Directory instances).

Semperis says DSP finds and rolls back unwanted changes to Active Directory objects and attributes in two minutes or less.

Semperis Directory Services Protector dashboard charting Active Directory changes over 30 days, with attack detection, indicators of compromise and a posture score. Source: semperis.com, October 2026.

Key features

  • Change tracking. Reads the changes domain controllers copy to each other (the replication stream). DSP catches changes that never reach Windows event logs, such as those from a fake domain controller (DCShadow).
  • Integrations. Opens ServiceNow tickets automatically and sends events to Splunk and Microsoft Sentinel.
  • Attack detection. Uses machine learning to detect password spraying, credential stuffing and other brute force attempts.
  • Service account protection. Finds and locks down the service accounts attackers abuse.

Pricing: Not published, and Semperis doesn’t advertise a free trial. Semperis offers a free Active Directory assessment tool called Purple Knight.

Rating: 4.8/5 on G2

Pros

  • Rolls back some unwanted Active Directory changes automatically.
  • Recommends fixes for Active Directory misconfigurations, and Semperis adds checks regularly.
  • Semperis support and customer success staff help with installation and answer questions quickly.

Cons

  • Built-in reports feel clunky, and notification options are limited.
  • DSP surfaces so many risks that deciding which to fix first can be hard.
  • Help text for some indicators of exposure (the checks DSP runs) could be clearer.

7. Proofpoint Identity Threat Defense

Proofpoint Identity Threat Defense suits large enterprises that want to remove the credentials an attacker could reuse after getting in. Proofpoint plants decoys on endpoints, such as fake files and fake saved browser credentials. Proofpoint alerts when an attacker uses a decoy but doesn’t block sign-ins. Proofpoint doesn’t offer a managed service.

Proofpoint says you can deploy more than 75 decoy types with no agents, sensors or changes to your systems.

Proofpoint Identity Threat Defense table of deception families, such as browsers, databases and files, with the techniques used and the number of decoys deployed. Source: proofpoint.com, October 2026.

Key features

  • Cached credential cleanup. Removes cached credentials and fixes misconfigurations on endpoints and servers.
  • Shadow admin discovery. Finds privileged accounts that your privileged access management (PAM) tool doesn’t manage.
  • Decoys. Treats any use of a decoy as a sign of compromise, because no real user has a reason to use a decoy.
  • Attack path mapping. Maps the routes an attacker could take from any endpoint to your most valuable systems.

Pricing: Not published, and Proofpoint doesn’t offer a free trial. Proofpoint offers a demo.

Rating: 4.5/5 on Gartner Peer Insights

Pros

  • Finds old cached credentials to delete, and risky permissions on unused or compromised accounts to revoke.
  • Detects stolen credentials used to move through the network, with few false positives.
  • Integrates with Microsoft Entra ID and Azure, and with SIEMs such as Splunk and IBM QRadar.

Cons

  • Connecting Proofpoint to your other tools is complex, and the detections need heavy tuning at first.
  • The first scan can find more cached credentials than your team can clean up at once.
  • Expensive, especially for small and mid-sized companies.

8. Sophos ITDR

Sophos ITDR suits teams already on Sophos XDR or Sophos MDR, because Sophos sells ITDR as an add-on to both. Sophos ITDR covers Entra ID and on-premises Active Directory.

Sophos ITDR also checks dark web markets, Telegram channels and stealer logs for your employees’ leaked credentials.

Sophos ITDR Top Findings panel listing Entra ID posture checks, such as password protection mode and conditional access policies. Source: docs.sophos.com, October 2026.

Key features

  • Posture checks. Checks Entra ID and Active Directory continuously for misconfigurations, for example in conditional access policies.
  • Leaked credential alerts. Raises a finding when a leaked password is newer than the user’s last password change.
  • Response actions. Forces password resets and locks accounts. With Sophos MDR, Sophos analysts also revoke active sessions.

Pricing: Not published. Sophos offers a 30-day free trial.

Rating: Not enough reviews on Gartner Peer Insights.

9. Okta Identity Threat Protection

Okta Identity Threat Protection suits companies that sign employees in through Okta Workforce Identity. Okta Identity Threat Protection keeps checking an account’s risk after sign-in, for the whole session.

When the risk rises, Okta can sign the user out of every supported app at once with Universal Logout. Supported apps include Google Workspace, Salesforce, Zoom and Box.

Okta Identity Threat Protection Universal Logout view signing a user out of several apps at once. Source: okta.com, October 2026.

Key features

  • Session risk detection. Detects signs of session hijacking, such as sign-ins from two countries minutes apart, or a device that stops meeting your security policy mid-session.
  • Automated response. Requires phishing-resistant MFA or ends the session when risk rises.
  • Token revocation. For Microsoft 365, Universal Logout revokes refresh tokens, which let an app get new access tokens without a sign-in. Open Microsoft 365 sessions end when their short-lived access tokens expire.
  • Shared signals. Exchanges security events with tools like CrowdStrike, Zscaler, Palo Alto Networks and Jamf.

Pricing: Not published. Okta lists Identity Threat Protection in its Professional suite, which is priced on request. Okta also sells Identity Threat Protection as an add-on to lower suites. Okta bills its suites annually, with a $1,500 annual minimum.

Rating: Not enough reviews. Okta’s reviews cover its sign-in products, not Identity Threat Protection.

10. Bitdefender GravityZone ITDR

Bitdefender GravityZone ITDR suits GravityZone endpoint customers who want identity alerts in the same XDR console as their endpoint alerts. Bitdefender sells the identity sensor as an add-on to GravityZone Business Security Enterprise and includes it in GravityZone Defense XDR.

GravityZone ITDR reads Kerberos, NTLM and LDAP events (the protocols Windows uses for sign-ins and directory lookups) from domain controllers, plus Entra ID and Intune (Microsoft’s device management) signals. GravityZone ITDR ties those events to endpoint incidents.

Bitdefender GravityZone incident graph showing an attack chain across user accounts and devices for a demo tenant. Source: bitdefender.com, October 2026.

Key features

  • Real-time blocking. Detects and blocks identity threats during lateral movement, using endpoint and identity data together.
  • Entra ID response. Marks a user as compromised in Entra ID. Your Entra ID risk policies can then block or challenge that user’s sign-ins.
  • Attack chain view. Builds the full attack chain and summarizes each incident in plain language.
  • Identity risks. Lists risky actions by active identities across Active Directory, Entra ID and service accounts.

Pricing: Not published. Bitdefender offers a free trial of GravityZone XDR.

Rating: Not enough reviews. G2 reviews cover the whole GravityZone platform, not GravityZone ITDR.

Selection criteria

How we evaluated these tools

We compared each tool on six points, using each vendor’s own site for features and pricing:

  • Identity coverage. Which of Active Directory, Entra ID, Okta and service accounts the tool protects.
  • Detection depth. Whether the tool catches Active Directory attacks like Pass-the-Hash and Golden Ticket, or only risky cloud sign-ins.
  • Blocking or alerts only. Whether the tool stops a risky sign-in as it happens, or only sends an alert.
  • Integrations. Whether detections reach your SIEM, SOAR or ticketing tools.
  • A managed option. Whether the vendor’s own analysts can watch alerts and respond for you.
  • Published pricing. Whether the vendor’s site lists a price.

Ratings, pros and cons come from the review site named in each entry, checked in October 2026.

How to choose a tool

Your situationShortlist
Mostly Microsoft (Active Directory and Entra ID)Microsoft Defender for Identity
Already on an endpoint platformYour endpoint vendor’s identity product (CrowdStrike, SentinelOne, Sophos or Bitdefender)
Cloud-first on OktaOkta Identity Threat Protection
Hybrid, with legacy systems that don’t support MFASilverfort
Active Directory changes you need to track and roll backSemperis Directory Services Protector
You want to remove cached credentials from endpoints and add decoysProofpoint Identity Threat Defense
No in-house security team watching alertsHuntress Managed ITDR

Before your demos, check whether your employees’ credentials are already compromised. In each demo, ask whether the tool blocks a sign-in with a leaked password or only raises an alert.

Start with your identity setup, then watch for leaked credentials

Pair your ITDR tool with dark web monitoring, so you can reset a leaked password before an attacker uses it. Run a free dark web scan to see which of your company’s credentials have already leaked. Then book a demo to see alerts for your domain or a client’s, including session cookies from stealer logs.

ITDR tools FAQs

ITDR (identity threat detection and response) monitors sign-ins and account changes in identity systems like Active Directory, Entra ID and Okta. XDR (extended detection and response) combines alerts from endpoints, email, network and cloud into one incident view. EDR (endpoint detection and response) covers endpoints, and NDR (network detection and response) covers network traffic. Several XDR vendors now sell ITDR as a module.
ITDR stands for identity threat detection and response. ITDR tools spot attacks on user and service accounts, such as a sign-in with a stolen password or a hijacked session. Every ITDR tool alerts your team, and some also block the sign-in or disable the account.
Ask whether your team would notice an attacker signing in to Active Directory, Entra ID or Okta with a stolen password. If not, you need ITDR, because EDR and firewalls don’t flag that sign-in. An ITDR tool also flags unusual account changes, such as a new admin account created overnight.
No. Huntress Managed ITDR is built for small businesses. Huntress analysts review the ITDR alerts and disable compromised accounts, so a small business doesn’t need an in-house security team.
Seven of the ten ITDR vendors on this list don’t publish a price. Huntress lists Managed ITDR at $4.80 per identity a month. Microsoft includes Defender for Identity in Microsoft 365 E5 at $60 per user a month. SentinelOne includes identity detection in Singularity Commercial at $229.99 per endpoint a year.
An ITDR tool flags a stolen credential when someone signs in with it. Sophos ITDR and SentinelOne Singularity Identity also check dark web sources for leaked credentials. Okta compares the credentials used at each sign-in against public breach lists. Compromised credential monitoring alerts you when an employee’s password or session cookie leaks, often before an attacker uses the stolen password or cookie.