All solutions
ITPIdentityby CrowdStrike

Falcon Identity Threat Protection

Attackers no longer break in: they log in. Detection has to look at identity, not only at the machine.

CrowdStrike
  • AD + Entra ID
    directories covered
  • Real time
    authentication traffic analysis
  • 0 agent
    on user endpoints

The problem it addresses

Most serious compromises run through a valid credential, not through malware. An EDR cannot see an attacker signing in with an administrator's password: from the endpoint's point of view, everything is legitimate. You have to look at the directory itself.

What is monitored

  • Directory hygiene

    Undocumented privileged accounts, service accounts whose password has never changed, dangerous Kerberos delegation, dormant accounts still enabled. The inventory alone is usually the first shock.

  • Authentication traffic

    Kerberos and NTLM requests analysed in real time. Credential theft and replay techniques show up here, where they are invisible elsewhere.

  • Lateral movement

    An account that suddenly starts authenticating to machines it has never touched draws a path. It is the most reliable signal of an intrusion in progress.

  • Conditional response

    Rather than blocking, requiring a second factor at the exact moment behaviour turns abnormal — including on legacy protocols that never supported one.

The useful side effect

The first inventory always surfaces years of accumulated debt: accounts of departed contractors, stacked administration groups, rights granted « just for this project » six years ago. The clean-up that follows reduces the attack surface more reliably than any detection rule.

Next step

A question? A project?

Our security specialists are available to you. A NextGen-SOC demonstration, an audit, or simply a conversation — start here.

Talk to our expertsBook a meetingWe reply within 24 hours