ClearSkies Identity Threat Protection

How ITP Decides

No individual signal is decisive on its own, and no individual signal can trigger an automated response by itself.

  • Six signal classes

    Evaluated in parallel, no single signal decisive

  • One risk score

    Weighted contributions, scored against the identity’s own baseline

  • Four risk bands

    Thresholds and enforcement configured per tenant

Multi-signal verification

A single false-positive suspension on a business-critical identity erodes trust faster than ten correct detections build it. Accuracy is therefore not a quality attribute of an identity capability, it is the precondition for the capability being allowed to act at all.

ITP evaluates each identity event across independent detection sources in parallel and combines their weighted contributions into a single identity risk score.

  1. Authentication anomaly

    Impossible travel, a new device, off-hours access, scored against the per-identity baseline

    WeightHigh

  2. Behavioral deviation

    First-time access, volume and scope anomalies, against a learned baseline held separately for human and non-human identities

    WeightHigh

  3. Privilege context

    Escalation, shadow administrative rights and service-account misuse, weighted more heavily for elevated identities

    WeightHigh

  4. Identity-attack signature

    Spraying, Pass-the-Ticket, Kerberoasting and token theft, from a maintained library mapped to ATT&CK

    WeightHigh

  5. Posture weakness

    A dormant administrator, absent multi-factor authentication or a non-expiring password, which raises standing risk and lowers the threshold for scrutiny

    WeightMedium

  6. Platform correlation

    A compromised host, a blocked domain or an exposed credential, supplied by the engine

    WeightMedium

Risk bands and what the workflow does

False positives arise almost always the same way: a tool alerts on one weak signal, an off-hours login or a new location, without the context to know whether it means anything. Figure 1 shows how a verdict is reached instead.

Risk bandWhat the workflow does
CriticalAt Critical, automated containment is permitted, covering disable, session revocation and forced reset, an alert fires, and the event is sent to the engine.
HighAt High, the finding is surfaced for immediate analyst action with one-click response available, and automated containment applies where tenant policy permits it.
MediumAt Medium, the finding is queued for triage, the identity is watched, and the event contributes to cumulative identity risk.
Low and informationalAt Low and informational, the event is retained for baselining and traceability, and no enforcement follows.
The signal classes, the risk bands, and the exchange with the TDIR engine

Figure 1. The signal classes, the risk bands, and the exchange with the TDIR engine.

Weighted scores map to bands, and the band determines what the workflow does rather than only how the finding is colored.

Band thresholds and the enforcement permitted at each band are configured per tenant, which is what allows one deployment to serve a regulated customer requiring analyst review of every action alongside a customer requiring containment without human latency.

Baselines retrain continuously against each tenant’s observed activity, and analyst verdicts feed back into them, so a benign pattern recorded as a false positive stops producing the same finding. Accuracy improves as a function of use rather than of rule maintenance, and the customer’s own environment defines what counts as normal within it.

Pre-investigated detections

Identity detections are pre-investigated before they reach a human. The AI-SecOps Autonomous Analysts gather the evidence an analyst would have gathered, namely the account’s baseline, its recent access history, the privilege it holds and the state of every host and domain in the event path, and then either escalate with a written rationale or close as benign with the same rationale recorded for audit. That reduces analyst burden rather than merely alert volume: suppression discards events that might have mattered, pre-investigation removes the reconstruction work instead.

In action: impossible travel and business email compromise

  • Problem

    A finance manager signs in at nine in the morning, having entered credentials into a phishing page the previous evening. Five minutes later a threat actor uses the same credentials to authenticate from another continent. The construction is illustrative rather than a customer incident.

  • Mechanism and outcome

    The authentication anomaly registers a physical impossibility, and behavioral deviation concurs, because the source address and device are absent from the account’s history. The engine corroborates against DNS Shield, which blocked the phishing domain resolved the previous evening, and against Attack Surface Monitoring, which had flagged the address in credential-exposure intelligence. Four signals concur, the score reaches the Critical band, and the playbook suspends the account and revokes its sessions within seconds.

Attackers no longer break in. They log in.

Response acts at the identity: disable, revoke, reset and step up, with a complete audit record.

Request a Demo