ClearSkies Identity Threat Protection
Detection Coverage
Eight detection families, each calibrated against a named failure mode and mapped to MITRE ATT&CK.
Agentless by default
Through the authenticated interfaces the identity sources already expose
On-premises by collector
iCollector forwards domain controller telemetry, nothing on the controllers
Human and non-human
Service and machine identities baselined separately
ITP maintains eight detection families.
An identity capability is only as credible as the named detections it ships.
Every detection carries a MITRE ATT&CK technique mapping, and every family is calibrated against the tenant’s own observed history rather than a fixed threshold.
Authentication abuse
Recognition of credential-guessing campaigns as campaigns
Session and token abuse
Detection of access obtained without the credential itself
Privilege and entitlement abuse
Escalation and standing-privilege drift surfaced while reversible
Service and machine identity misuse
Detection of hijacked automation credentials
Directory attack techniques
Detection of attacks against the directory itself
Identity posture weakness
Continuous assessment of the conditions that let attacks succeed
Insider and data-access anomaly
Detection of legitimate access used illegitimately
Third-party and federated identity risk
Monitoring of identities the organization does not employ
How Coverage Reaches
Every Identity
Partial coverage is the failure mode of identity defense. An environment monitored in the cloud but not on premises, or for human accounts but not for service accounts, produces a detection surface with exactly the shape an attacker needs.
The majority of coverage is agentless. ITP consumes authentication, directory and entitlement telemetry through the authenticated interfaces the identity sources already expose, so an environment can be brought under monitoring without touching an endpoint build or a golden image.

Supported identity sources
| Platform class | Supported sources | Collection method |
|---|---|---|
| On-premises directory | Active Directory Domain Services | iCollector forwarder |
| Cloud identity provider | Entra ID, Okta | Agentless API and audit stream |
| Cloud identity and access management | AWS IAM, Azure RBAC, Google Cloud IAM | Agentless API |
| Federated access | SAML and OIDC applications behind a monitored provider | The provider’s authentication record |
| Human resources and identity ownership | Major HR platforms through a connector | Agentless API |
| Endpoint corroboration | The ETMR agent, or endpoint telemetry through the engine | Agent |
The Seven Pillars
Evaluators no longer ask whether a capability flags failed logins. They ask whether it meets the criteria that separate a continuously operating identity defense program from a directory with alerting attached.
Authentication and access monitoring
Every authentication and authorization event, in real time, from on-premises directories, cloud identity providers and federated access, for human, service and machine identities alike, normalized into one event stream.
Identity behavioral analytics
A learned baseline per user and per service account, covering login times, locations, devices and access, and detection of deviation against it.
Privileged-access monitoring
Dedicated scrutiny for elevated accounts: escalation, group-membership change, service-account misuse and standing or shadow administrative rights, with anomalies on those identities treated as higher severity.
Identity-attack and posture detection
A maintained library covering credential stuffing, password spraying, Pass-the-Ticket, Kerberoasting, token theft and account manipulation, alongside continuous posture assessment for dormant high-privilege accounts, non-expiring passwords and absent multi-factor authentication.
Contextual enrichment
Identity context injected automatically into alerts raised elsewhere: the account, its role, its privilege, its current risk and its recent access, with a per-identity risk score that travels with every correlated event.
Identity-centric response
Response modeled at the identity as well as at the host: suspend or disable, revoke sessions, force a reset, trigger step-up authentication, as one-click analyst actions and as automated playbooks, with a full audit record.
Integration with the engine and with a SIEM
A normalized schema, real-time push and pull-based transports, MITRE ATT&CK tagging on every applicable detection, and correlation identifiers preserved end to end, so an analyst can pivot from an alert back to the identity evidence without a manual lookup.
MITRE ATT&CK and supported frameworks
Identity is a thread running the length of the ATT&CK matrix rather than a single tactic within it. ITP maps every detection to the relevant technique, which aligns detection, hunting and reporting to a framework that boards, auditors and regulators already accept.
| Detection family | ATT&CK tactic | Technique identifiers |
|---|---|---|
| Authentication abuse | Initial Access, Credential Access | T1110, T1110.003, T1621, T1078 |
| Session and token abuse | Initial Access, Defense Evasion, Lateral Movement | T1550, T1539, T1078, T1021 |
| Privilege and entitlement abuse | Privilege Escalation, Persistence | T1548, T1098, T1078.002 |
| Service and machine identity misuse | Privilege Escalation, Persistence | T1078.003, T1136 |
| Directory attack techniques | Credential Access, Discovery | T1558, T1003, T1207, T1087, T1069 |
| Identity posture weakness | Preventive, mapped to Initial Access exposure | T1078 as exposure |
| Insider and data-access anomaly | Collection, Exfiltration | T1530, T1213, T1020 |
| Third-party and federated identity risk | Initial Access, Persistence | T1199, T1078.004 |
Mapping is scope, not an assurance of detection. The mapping is representative rather than exhaustive, and a technique listed is claimed rather than demonstrated. Coverage is exported as a MITRE ATT&CK Navigator layer the customer can load and verify independently.
Identity detections and posture findings map to NIST CSF, ISO 27001, NIS2, DORA, GDPR and the EU Cyber Resilience Act as evidence is produced, so audit preparation draws on the same record the security operation works from. Control-level mapping is held by the Regulatory Frameworks core function. Framework mapping supports audit and reporting; it is not a certification, and deployment of ITP alone does not establish compliance with any framework.
Attackers no longer break in. They log in.
Coverage reaches on-premises directories, cloud identity providers and federated access, for human, service and machine identities alike, with the boundary stated explicitly rather than implied.
Request a Demo
