Academy Central
----
Weather

Identity Threat Detection and Response (ITDR)

身分威脅偵測與回應(ITDR)

Overview | 概述

Identity-based attacks are among the most common and effective methods for threat actors to gain unauthorized access. ITDR detects and responds to identity-related security threats by monitoring user authentication and access behaviors across integrated SaaS applications.

身分型攻擊是威脅行為者取得未授權存取最常見且最有效的方法之一。ITDR 透過監控整合 SaaS 應用程式中的使用者驗證和存取行為來偵測和回應身分相關的安全威脅。


Identity-Based Attack Techniques | 身分型攻擊技術

TechniqueDescription技術說明
Credential TheftStealing credentials via phishing, malware憑證竊取透過網路釣魚、惡意軟體竊取憑證
Brute ForceAutomated password guessing暴力破解自動化密碼猜測
Password SprayingTesting common passwords across accounts密碼噴灑跨帳戶測試常用密碼
Session HijackingTaking over authenticated sessionsSession 劫持接管已驗證的 Session
OAuth AbuseExploiting OAuth grants for persistent accessOAuth 濫用利用 OAuth 授予取得持久存取
Privilege EscalationGaining higher access than authorized權限提升取得超越授權的存取權
Account TakeoverCompletely compromising a user account帳戶接管完全入侵使用者帳戶
AiTMIntercepting authentication flows中間人攻擊攔截驗證流程

Key Insight | 關鍵洞察: Identity threats often manifest as subtle anomalies rather than obvious attacks. Look for unusual patterns — logins from new locations, odd-hour access — not just failed login attempts.

關鍵洞察: 身分威脅通常表現為微妙的異常而非明顯的攻擊。關注異常模式 — 來自新位置的登入、異常時間的存取 — 而不僅僅是失敗的登入嘗試。


ITDR Detection Methods | ITDR 偵測方法

MethodDescription方法說明
Behavioral AnalysisIdentifies unusual login patterns and activities行為分析識別異常的登入模式和活動
Impossible Travel DetectionFlags logins from physically impossible locations不可能旅行偵測標記來自物理上不可能位置的登入
Brute Force & Password Spray DetectionIdentifies authentication attacks暴力破解與密碼噴灑偵測識別驗證攻擊
AiTM DetectionIdentifies sophisticated phishing campaigns中間人偵測識別複雜的網路釣魚活動

Threat Center | 威脅中心

The Threat Center serves as a dedicated hub for identity-based threats and IOCs detected across your SaaS ecosystem.

威脅中心是跨 SaaS 生態系統偵測到的身分型威脅和 IOC 的專屬中心。

Threat Categorization | 威脅分類

Threats are categorized by type, severity, and affected applications.

威脅按類型嚴重程度受影響應用程式分類。

Threat Details | 威脅詳情

Each threat includes: affected users, detection time, and specific indicators that triggered the detection.

每個威脅包括:受影響使用者偵測時間和觸發偵測的特定指標

MITRE ATT&CK Mapping | MITRE ATT&CK 映射

Threats mapped to MITRE ATT&CK provide context about tactics and techniques being used, helping anticipate attacker next steps.

映射到 MITRE ATT&CK 的威脅提供關於正在使用的策略和技術的上下文,協助預測攻擊者的下一步。

Recommended Actions | 建議行動

Guidance is provided on how to respond to each type of threat, tailored to the specific characteristics of each threat.

針對每種威脅的具體特徵提供回應指引。

Historical Analysis | 歷史分析

View threat trends over time to identify patterns and persistent threats.

檢視威脅趨勢以識別模式和持續性威脅。

How to Use the Threat Center | 如何使用威脅中心

StepAction步驟操作
1Review — Check for new threats regularly1審查 — 定期檢查新威脅
2Prioritize — Focus on severity and affected users2優先排序 — 關注嚴重程度和受影響使用者
3Investigate — Use threat details for high-priority items3調查 — 使用威脅詳情處理高優先級項目
4Review Recommendations — Follow suggested actions4審查建議 — 遵循建議的行動
5Track — Monitor trends over time5追蹤 — 隨時間監控趨勢

Events Monitor | 事件監視器

The Events Monitor helps you visualize, explore, and refine insights from actions and actors in your SaaS environment.

事件監視器協助視覺化、探索和優化對 SaaS 環境中操作和參與者的洞察。

Key Features | 關鍵功能

FeatureDescription功能說明
Unified Activity LogConsolidated view across all apps統一活動日誌跨所有應用程式的整合視圖
Advanced FilteringFocus on specific users, apps, time periods進階篩選關注特定使用者、應用程式、時間段
Contextual InformationUser details, location, device data情境資訊使用者詳情、位置、裝置資料
Timeline AnalysisChronological view of activities時間線分析活動的時間順序視圖
Anomaly HighlightingAutomatic detection of unusual activities異常高亮自動偵測異常活動

Configuring Alerts | 設定警報

Falcon Shield detects common identity attack patterns by continuously monitoring authentication and access behaviors.

Falcon Shield 透過持續監控驗證和存取行為來偵測常見的身分攻擊模式。

Common Attack Patterns to Monitor | 需監控的常見攻擊模式

PatternScenarioBehaviors to Monitor模式情境需監控的行為
Account TakeoverPhishing → stolen credentials → MFA bypassMultiple failed logins → success from unusual location → password/MFA changes帳戶接管網路釣魚 → 竊取憑證 → 繞過 MFA多次失敗登入 → 從異常位置成功 → 密碼/MFA 變更
Privilege EscalationMisconfigured role → creates admin accountAdded to privileged roles → sudden permission increase → new admin accounts權限提升被賦予特權角色 → 權限突然增加 → 建立新管理員帳戶
Persistent AccessCompromised admin → creates hidden service accountOAuth apps with excessive permissions → secondary auth methods → long-lived credentials持久存取管理員被入侵 → 建立隱藏服務帳戶 → 建立帶有過度權限的 OAuth 應用程式
Data ExfiltrationCompromised account → auto-copies docs externallyMass downloads → unusual external sharing → data export → access outside job function資料外洩帳戶被入侵 → 自動複製文件到外部 → 大量下載 → 異常外部分享
Anomaly HighlightingImpossible travel → automated responseLogins from impossible locations → account suspension → investigation異常高亮不可能旅行 → 自動回應 → 從不可能的位置登入

Threat Investigation Flow | 威脅調查流程


Integration with Falcon Identity Protection | 與 Falcon 身分保護整合

When deployed alongside Falcon Identity Protection, enhanced detection capabilities span:

與 Falcon 身分保護一起部署時,增強的偵測能力涵蓋:

  • On-premises directories (Active Directory)

  • Cloud identity providers (Okta, Azure AD)

  • SaaS applications (Salesforce, Office 365, Google Workspace)

  • 本機目錄(Active Directory)

  • 雲端身分提供者(Okta、Azure AD)

  • SaaS 應用程式(Salesforce、Office 365、Google Workspace)


Related Modules | 相關模組

ModuleDescription關聯模組說明
User InventoryIdentity risk assessment使用者清單身分風險評估
Identity GovernanceGovernance and compliance framework身分治理治理與法規遵循框架
Permissions GovernanceLeast privilege enforcement權限治理最小權限實施
Devices InventoryDevice-based access control裝置清單基於裝置的存取控制