Identity Threat Detection — your credentials are the target.
80% of breaches involve compromised credentials (Verizon DBIR 2025). Attackers don't hack in — they log in. SignalPoint's identity threat detection monitors your Active Directory, cloud identity, and SaaS accounts for the signs of credential abuse, privilege escalation, and account takeover.
Attackers don't break in. They log in — using credentials stolen from your employees, purchased on criminal markets, or obtained through phishing.
Identity-based attacks have become the dominant attack vector precisely because credential theft bypasses most perimeter and endpoint defenses. An attacker who logs into your VPN with a valid employee credential doesn't trigger a firewall alert. They look like a legitimate user. The question is whether you have behavioral monitoring in place that detects when a "legitimate" login is actually an attacker — based on where they're logging in from, what they're doing after login, and how their behavior compares to baseline.
SignalPoint's identity threat detection monitors your Active Directory domain, Azure AD / Entra ID, Okta, and other identity providers for behavioral indicators of credential compromise, privilege escalation attempts, and account takeover — alerting analysts who investigate immediately.
What we monitor
- Impossible travel: authentication from two geographically distant locations within an impossibly short timeframe
- Anomalous login hours: authentication outside a user's established patterns, particularly at night or on weekends
- Privilege escalation: unusual assignment of administrative roles or addition to privileged groups
- Pass-the-hash and pass-the-ticket attacks: credential relay attacks targeting Windows authentication
- Kerberoasting: requests for service tickets for accounts with weak passwords, a precursor to credential cracking
- DCSync attacks: unauthorized replication of the Active Directory database to extract password hashes
- MFA fatigue: repeated MFA push notifications designed to exhaust a user into approving a malicious login
- Credential stuffing: automated login attempts using credentials from breach databases against corporate SSO
- Service account abuse: privileged service accounts used for interactive logins or from unusual systems
Identity threat response
When an identity threat is confirmed, SignalPoint responds immediately: forcing session termination, locking compromised accounts, revoking active tokens, initiating forced password resets, and coordinating with your IT team on credential hygiene across all connected services. Identity threats require a different response workflow than endpoint threats — we're experienced in both.
Common questions.
SignalPoint monitors on-premises Active Directory, Azure AD/Microsoft Entra ID, Okta, Google Workspace, and other identity providers depending on your environment. We also monitor SaaS application authentication logs where available. Contact us to discuss your specific identity stack.
Monitoring for login failures (failed authentication) is a basic control that catches unsophisticated attacks. Identity threat detection goes much further — behavioral analysis of successful authentications, privilege escalation monitoring, detection of credential relay attacks, and analysis of authentication patterns against user baselines. Sophisticated attackers who have valid credentials generate successful logins, not failures.