The Attack Moved to the Login Screen
For a decade, breaking into a business meant getting malware onto a machine. Endpoint detection got good enough at catching that, so attackers changed target. Today the fastest way into most small businesses is not the laptop — it is the Microsoft 365 or Google Workspace account, reached with a stolen password, a phished session token, or a malicious app the user was tricked into approving.
The reason this works is that it never touches an endpoint. An attacker who steals a live session token does not need your password, and does not trip your antivirus, because from the cloud’s point of view they are you. They read mail, set up quiet forwarding rules, approve their own OAuth app for permanent access, and wait. The endpoint tools you already pay for — including the Huntress Managed EDR on your machines — simply cannot see any of it, because none of it happens on a machine they watch.
Identity Threat Detection and Response (ITDR) is the category built to close that specific gap. It watches the identity layer — sign-ins, tokens, app grants, mailbox rules — the way EDR watches the endpoint.
What Huntress ITDR Watches
Huntress groups its identity detections into three areas, each mapped to a real attacker move rather than an abstract risk score.
Unwanted Access
Account takeover, suspicious and impossible-travel logins, VPN and anonymizer abuse, and session hijacking — where an attacker imports your stolen session token into their own browser and skips the password and MFA entirely. This is the core of modern adversary-in-the-middle phishing, and it is invisible to a password reset.
Rogue Apps
Malicious OAuth applications are the stealthiest identity attack there is: a user approves an app once, and it keeps its access even after the password changes and MFA is reset. Huntress inventories every app connected to your tenant and flags the malicious and risky ones with clear removal steps.
Shadow Workflows
Business email compromise is not only about tricking a user — it is about quietly owning the inbox. Huntress catches the hidden forwarding rules and mailbox manipulations attackers set up to siphon mail and run invoice-fraud schemes without the owner ever noticing.
Why It Belongs Next to Your Endpoint Coverage
EDR and ITDR are not competing products; they cover two halves of the same environment. One watches the machines, the other watches the accounts, and a serious attack usually crosses between them. A phished token leads to a mailbox rule; a compromised laptop leads to a harvested credential. Running one without the other leaves a blind spot exactly where attackers have learned to operate.
- Microsoft 365 and Google Workspace — ITDR protects both identity platforms from one console and one SOC, so a business on either (or migrating between them) is covered.
- Read-only OAuth connection — there is no agent to deploy on the identity side. Huntress connects to your tenant through a secure, read-only Microsoft or Google integration, and onboarding takes a matter of days.
- Every alert is human-validated — the same 24/7 Huntress SOC that reviews endpoint alerts reviews identity alerts, so your team hears about confirmed takeovers, not a stream of login noise.
- Automated containment — for a confirmed account takeover, the response can disable the compromised account automatically, with a stated mean time to respond of about three minutes rather than the hours a human-only process takes.
How Tomotechi Runs It for You
Huntress supplies the detections and the SOC. We supply the part that turns an alert into a resolved incident for a business that does not have a security analyst on staff.
Onboarding and hardening
We connect ITDR to your tenant and, first, review the conditional access, MFA enforcement, and sharing settings it will be watching — closing the easy gaps before turning on detection.
We are your analyst
Confirmed-incident alerts route to the Tomotechi help desk on a defined escalation path. You do not need to staff a security desk to act on them — that is our job.
Incident response to closure
When an identity is compromised, we drive the response — account lockout, token revocation, rule cleanup, rogue-app removal — through to a closed ticket, coordinating with the SOC throughout.
ITDR is available on its own, but most businesses run it alongside endpoint coverage as the Endpoint + Identity tier, which is the configuration that matches where attacks actually land today. See the full breakdown on our Huntress offerings page, or the mechanics on our implementation page.
Is Identity Your Real Exposure?
A few questions worth sitting with. If the answer to any is yes, the identity layer is where your next incident is most likely to start:
- Do you run Microsoft 365 or Google Workspace for company email? (Almost certainly yes.)
- Does anyone with the authority to move money, or approve an invoice, use it?
- Could a member of staff be phished into approving a login or an app on a convincing-looking page?
- Would you currently know if a hidden forwarding rule were quietly copying an executive’s mail to an outside address?
The uncomfortable part of identity attacks is that everything keeps working normally while they happen. There is no ransom note and no locked screen — just an attacker reading along, until the day an invoice gets paid to the wrong account.
Put a Watch on Your Identities
Tell us whether you run Microsoft 365, Google Workspace, or both, and how many users you have, and we’ll scope Huntress ITDR for your environment.
Protect Our Identities → See Plans & Tiers →
Or call 281-407-1619 and we’ll talk through where your identity exposure actually sits.