Identity threat detection and response (ITDR): Defender for Identity monitors identity infrastructure to detect, investigate, and respond to identity-based attacks, focusing protection on the credentials and directory systems attackers target.
02
Monitoring of Active Directory for suspicious activity: Using sensors on domain controllers, the platform observes authentication and directory activity in real time, watching for behavior that indicates compromise or attack.
03
Detection of identity-based attacks (Pass-the-Hash, Pass-the-Ticket, Golden Ticket): The platform recognizes the signatures and behaviors of credential-theft and ticket-forgery techniques, alerting on attacks that abuse Kerberos and NTLM authentication.
04
Lateral movement path detection: Defender for Identity maps and surfaces potential lateral movement paths that could let an attacker move from a compromised account toward sensitive accounts, highlighting risky exposure before it is exploited.
05
Reconnaissance and enumeration detection: The platform detects reconnaissance activity such as account, group, and resource enumeration that attackers perform early in an intrusion to map the environment.
Your plan caps how many capabilities are shown — upgrade to see the full list