ClearSkies Identity Threat Protection

Detection Coverage

Eight detection families, each calibrated against a named failure mode and mapped to MITRE ATT&CK.

  • Agentless by default

    Through the authenticated interfaces the identity sources already expose

  • On-premises by collector

    iCollector forwards domain controller telemetry, nothing on the controllers

  • Human and non-human

    Service and machine identities baselined separately

ITP maintains eight detection families.

An identity capability is only as credible as the named detections it ships.

Every detection carries a MITRE ATT&CK technique mapping, and every family is calibrated against the tenant’s own observed history rather than a fixed threshold.

  1. Authentication abuse

    Recognition of credential-guessing campaigns as campaigns

    Primary engineStatistical and threshold analytics across the tenant

  2. Session and token abuse

    Detection of access obtained without the credential itself

    Primary engineSession correlation and geo-velocity analytics

  3. Privilege and entitlement abuse

    Escalation and standing-privilege drift surfaced while reversible

    Primary engineEntitlement state comparison with behavioral scoring

  4. Service and machine identity misuse

    Detection of hijacked automation credentials

    Primary engineA dedicated non-human baseline model

  5. Directory attack techniques

    Detection of attacks against the directory itself

    Primary engineSignature and protocol-behavior analytics

  6. Identity posture weakness

    Continuous assessment of the conditions that let attacks succeed

    Primary engineConfiguration state assessment

  7. Insider and data-access anomaly

    Detection of legitimate access used illegitimately

    Primary engineVolume and scope deviation against baseline

  8. Third-party and federated identity risk

    Monitoring of identities the organization does not employ

    Primary engineFederated-trust analytics with posture assessment

How Coverage Reaches
Every Identity

Partial coverage is the failure mode of identity defense. An environment monitored in the cloud but not on premises, or for human accounts but not for service accounts, produces a detection surface with exactly the shape an attacker needs.

The majority of coverage is agentless. ITP consumes authentication, directory and entitlement telemetry through the authenticated interfaces the identity sources already expose, so an environment can be brought under monitoring without touching an endpoint build or a golden image.

ClearSkies iISOC identity source connections: directories, cloud identity providers and federated access under monitoring
  • On-premises Active Directory

    Domain controller security event telemetry is collected through iCollector, deployed as a lightweight forwarder inside the customer network. Nothing is installed on the domain controllers themselves beyond standard audit policy configuration.

  • Endpoint corroboration

    Process, session and host context that allows an identity verdict to be confirmed against what happened on the machine requires the ETMR agent, or an equivalent endpoint source connected to the engine. ITP detects without it; the endpoint layer is what turns a behavioral verdict into a confirmed one.

  • Out of scope

    ITP does not observe local accounts on unmanaged devices that authenticate against no monitored directory, or application-internal user records with no representation in a connected identity source, such as a legacy application maintaining its own user table.

  • What is never collected

    Credential material of any kind: passwords, password hashes, private keys, certificates and token secrets are neither collected nor transmitted. Nor is the content of files, messages or records accessed by a monitored identity, nor the payload of authenticated sessions, nor directory objects outside the authorized scope, which is enforced at the connector. What ITP transmits is authentication and authorization metadata together with the verdicts derived from it. The full data-handling position is in ClearSkies iISOC Data Sovereignty.

Supported identity sources

Platform classSupported sourcesCollection method
On-premises directoryActive Directory Domain ServicesiCollector forwarder
Cloud identity providerEntra ID, OktaAgentless API and audit stream
Cloud identity and access managementAWS IAM, Azure RBAC, Google Cloud IAMAgentless API
Federated accessSAML and OIDC applications behind a monitored providerThe provider’s authentication record
Human resources and identity ownershipMajor HR platforms through a connectorAgentless API
Endpoint corroborationThe ETMR agent, or endpoint telemetry through the engineAgent

The Seven Pillars

Evaluators no longer ask whether a capability flags failed logins. They ask whether it meets the criteria that separate a continuously operating identity defense program from a directory with alerting attached.

Authentication and access monitoring

Every authentication and authorization event, in real time, from on-premises directories, cloud identity providers and federated access, for human, service and machine identities alike, normalized into one event stream.

Identity behavioral analytics

A learned baseline per user and per service account, covering login times, locations, devices and access, and detection of deviation against it.

Privileged-access monitoring

Dedicated scrutiny for elevated accounts: escalation, group-membership change, service-account misuse and standing or shadow administrative rights, with anomalies on those identities treated as higher severity.

Identity-attack and posture detection

A maintained library covering credential stuffing, password spraying, Pass-the-Ticket, Kerberoasting, token theft and account manipulation, alongside continuous posture assessment for dormant high-privilege accounts, non-expiring passwords and absent multi-factor authentication.

Contextual enrichment

Identity context injected automatically into alerts raised elsewhere: the account, its role, its privilege, its current risk and its recent access, with a per-identity risk score that travels with every correlated event.

Identity-centric response

Response modeled at the identity as well as at the host: suspend or disable, revoke sessions, force a reset, trigger step-up authentication, as one-click analyst actions and as automated playbooks, with a full audit record.

Integration with the engine and with a SIEM

A normalized schema, real-time push and pull-based transports, MITRE ATT&CK tagging on every applicable detection, and correlation identifiers preserved end to end, so an analyst can pivot from an alert back to the identity evidence without a manual lookup.

MITRE ATT&CK and supported frameworks

Identity is a thread running the length of the ATT&CK matrix rather than a single tactic within it. ITP maps every detection to the relevant technique, which aligns detection, hunting and reporting to a framework that boards, auditors and regulators already accept.

Detection familyATT&CK tacticTechnique identifiers
Authentication abuseInitial Access, Credential AccessT1110, T1110.003, T1621, T1078
Session and token abuseInitial Access, Defense Evasion, Lateral MovementT1550, T1539, T1078, T1021
Privilege and entitlement abusePrivilege Escalation, PersistenceT1548, T1098, T1078.002
Service and machine identity misusePrivilege Escalation, PersistenceT1078.003, T1136
Directory attack techniquesCredential Access, DiscoveryT1558, T1003, T1207, T1087, T1069
Identity posture weaknessPreventive, mapped to Initial Access exposureT1078 as exposure
Insider and data-access anomalyCollection, ExfiltrationT1530, T1213, T1020
Third-party and federated identity riskInitial Access, PersistenceT1199, T1078.004

Mapping is scope, not an assurance of detection. The mapping is representative rather than exhaustive, and a technique listed is claimed rather than demonstrated. Coverage is exported as a MITRE ATT&CK Navigator layer the customer can load and verify independently.

Identity detections and posture findings map to NIST CSF, ISO 27001, NIS2, DORA, GDPR and the EU Cyber Resilience Act as evidence is produced, so audit preparation draws on the same record the security operation works from. Control-level mapping is held by the Regulatory Frameworks core function. Framework mapping supports audit and reporting; it is not a certification, and deployment of ITP alone does not establish compliance with any framework.

Attackers no longer break in. They log in.

Coverage reaches on-premises directories, cloud identity providers and federated access, for human, service and machine identities alike, with the boundary stated explicitly rather than implied.

Request a Demo