惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
N
Netflix TechBlog - Medium
罗磊的独立博客
博客园 - 聂微东
美团技术团队
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
Recent Commits to openclaw:main
Recent Commits to openclaw:main
博客园_首页
宝玉的分享
宝玉的分享
G
GRAHAM CLULEY
Microsoft Azure Blog
Microsoft Azure Blog
量子位
SecWiki News
SecWiki News
F
Fortinet All Blogs
J
Java Code Geeks
S
SegmentFault 最新的问题
V
V2EX
Martin Fowler
Martin Fowler
F
Full Disclosure
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
P
Proofpoint News Feed
S
Security Affairs
Application and Cybersecurity Blog
Application and Cybersecurity Blog
K
Kaspersky official blog
S
Secure Thoughts
S
Schneier on Security
MongoDB | Blog
MongoDB | Blog
博客园 - 三生石上(FineUI控件)
Cloudbric
Cloudbric
雷峰网
雷峰网
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Cloudflare Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
爱范儿
爱范儿
V2EX - 技术
V2EX - 技术
H
Hackread – Cybersecurity News, Data Breaches, AI and More
腾讯CDC
阮一峰的网络日志
阮一峰的网络日志
Apple Machine Learning Research
Apple Machine Learning Research
H
Help Net Security
C
Check Point Blog
T
The Blog of Author Tim Ferriss
D
DataBreaches.Net
Hacker News - Newest:
Hacker News - Newest: "LLM"
G
Google Developers Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
T
Tenable Blog
博客园 - 【当耐特】

Todyl Blog

CyberChef: How to Decode & Decrypt Malicious Scripts (Step-by-Step Guide) Achieving Zero Trust with SASE: A Practical Roadmap for Modern Network Securityso like MSP Security Maturity Assessment: Why 79% of MSPs Are Stuck in 2025 The Rising Threat of Malicious AI: What Every Organization Needs to Know Iran Cyber Threat 2026: What SMBs and MSPs Need to Know The OneStart AI Browser Deception Cyber Insurance Requirements Based on Industry Why Third-Party Security Certification Is Your MSP's Competitive Edge Why Cyber Insurance Carriers Are Shifting to Security Assurance Iran Conflict and Cyber Risk: What North American Organizations Need to Know ‍ Why Cyber Resilience Requires Security, Compliance, and Insurance MSP Security Services: How to Position Identity Protection as Competitive Advantage Identity Security Gap Assessment: A Step-by-Step Guide for MSPs How Credential Theft Attacks Are Costing MSP Clients Millions Do I Need Cyber Insurance as a Small Business? Advanced Persistent Threats (APTs) Explained Preparing for CMMC Level 1: What Your Organization Needs to Do The Real Cost of Doing Nothing in Cybersecurity MSP Security: Build vs Buy SOC The Rise of a Cybercrime Alliance: What LockBit, Qilin, and DragonForce Mean for Business Risk Cyber Threat Recovery Strategies for MSPs What MSPs Need to Know about CIRCIA Final Rule ClickFix: The Evolution of Copy-Paste Social Engineering Akira Ransomware: Threat Assessment of a Scalable RaaS Operation The Dos and Don’ts of Applying for a Cyber Insurance Policy What Is Threat Hunting? A Practical Guide for MSPs and SMBs The Business Case for Cyber Threat Management Evaluating Free and Open Source SIEM Tools in 2026 How organizations can combat BEC Using SASE to help meet cyber insurance requirements Introducing the Anomaly Framework Security Operations Over Tools Beyond Tools: A Strategic Approach to Data Security Cyber Threat Response Strategies for MSPs Threat Advisory: Email Account Compromise BECs In the Wild: When Millions of People Are Expecting the Same Email Michigan and Wisconsin Proposed Age Verification Bills and the Impact on VPNs and SASE: What You Need to Know Cyber Threat Detection Strategies for MSPs Cyber Threat Prevention Strategies for MSPs Simplifying CMMC Level 1 with Todyl GRC How to Complete Your CMMC Level 1 Self-Assessment: A Step-by-Step Walkthrough Cyber Threats Don't Take Time Off How MSPs Build Lasting Client Relationships Through Proactive Operations Risk Management for MSPs: Why Business Context Changes Everything 5 Pillars for Security Program Growth in 2025 One Action MSPs can take to Address Risk and Secure Clients Building Resilience in a Perimeter-less World with Defense-in-Depth Aligning Technology Implementation to Business Outcomes Top 5 Myths about Cybersecurity How Conditional Access Transforms Your Cybersecurity Program Why MSPs need to embrace a prescriptive model How Texas SB 2610 Positions MSPs as Strategic Risk Advisors Simplifying cybersecurity maturity with managed cloud SIEM Addressing firewall vulnerabilities Understanding the Pitfalls of RDP MSP Zero-Day Response Plan: When Security Tools Can't Help You Old is Gold: Tackling Persistent Vulnerabilities How MXDR drives operational efficiencies Using SASE for secure remote access How to find the best endpoint security solution The Cyber Insurance Crisis: Why MSPs and Their Clients Are Struggling What to ask of a prospective endpoint security vendor Thinking Red, Acting Blue: Turning Attack Tactics in Your Favor Zero-Day Attacks and False Alarms: Lessons for MSPs Dissecting the Recent Rise in 2025 Zero Days MSP Security Monitoring Strategy: Identity and Cloud Blind Spots Introducing the Todyl Community: A Collaborative Platform for MSPs Threat Advisory: PDFast Freeware Compromise Navigating Today’s Cybersecurity Threat Landscape: Where MSPs Should Start Threat Advisory: Understanding the Recent SonicWall SSL VPN Vulnerability and How to Protect Your Clients Partner Spotlight: GoTech IT Solutions Threat Advisory: SQL Injection in FortiClient CVE-2023-48788 The Importance of SSL Inspection Navigating Compliance Frameworks: Common Challenges and Effective Solutions Making the most of SASE Web Filtering Iran & Middle-East Geopolitical Shifts: Emerging Cyber Risks for SMBs MSP Security KPIs That Matter: Beyond Vanity Metrics to Business Outcomes MSP Challenges Looking into 2025 Combining EDR and NGAV for Defense-in-Depth Starting Your Security Framework Journey: A Practical Implementation Guide Cyber Insurance vs. Warranties: Key Risk Management Elements Akira Ransomware: A Persistent Threat to MSP Operations Transforming Cyber Insurance for MSPs and Their Clients Two Truths, Double Whammy: Why Vulnerability Remediation Needs a Rethink Using LAN ZeroTrust for segmentation The role of SIEM in incident response Partner Spotlight: 917 Solutions Threat Advisory: Business Email Compromise Campaign using OVPN for Obfuscation Beyond Implementation: Creating an Ongoing Security Framework Program ClickFix: Fake Captcha Leads to Real Damage Streamlining Security and Compliance Information Gathering with Assessments EpiBrowser: A Sophisticated PUP Masquerading as Chromium Partner Spotlight: AnchorSix Tips to Help MSPs Set Goals for the New Year How SIEM helps detect insider threats Massive Wave of Network Security Vulnerabilities Demands Immediate Action FortiJump: The FortiManager Zero-Day Vulnerability Explained Use cases of SASE: Software-defined perimeter Threat Advisory: LightPerlGirl Malware Why MSPs Must Prioritize CIS Critical Security Controls v8.1 for Client Success
Stopping Identity Threats with ITDR through MXDR
2026-01-09 · via Todyl Blog

Digital identities remain the most targeted aspect of any organization. They are the keys to the kingdom, enabling access to systems, applications, and other business-critical accounts. Unfortunately, rises in phishing and business email compromise (BEC) put identities at great risk. Businesses need to take every step they can to keep them protected from these cyber threats.

Identity threat detection and response (ITDR) is a powerful method for preventing account takeovers (ATO) and other identity threats. But strong ITDR requires continuous monitoring to ensure that identities remain safe, even outside business hours. This is often easier said than done.

That’s why many organizations turn to Managed Extended Detection and Response, or MXDR, for their 24/7 ITDR needs. Let’s explore how MXDR proves useful in the fight against identity threats by understanding their prevalence in the first place.

The Constant Identity Threat

Because they grant access to key resources, identities are a primary target for threat actors. Attackers can obtain these credentials through multiple avenues.

Phishing

One of the most prevalent identity threats is phishing. Using social engineering tactics, attackers trick end users into giving up their credentials.

Attackers often pretend to be Microsoft or other well-known brands to trick people into clicking fake links. The websites they lead to use social engineering to harvest users' identities.

After the user gives up their credentials, the attacker can use the identity for account takeovers. Then, they can use the stolen credentials to gain access to their Microsoft 365 account and commit BEC. The result is more sophisticated phishing campaigns, inbox snooping, account misuse, etc.

Adversary-in-the-Middle (AitM)

Besides phishing, attackers will prey on identities by intercepting a user’s traffic to steal credentials and session tokens. This Adversary-in-the-Middle (AitM) technique preys on people using unsafe public networks (i.e. airports or coffee shops). The threat actor steals traffic data by taking over the public router.

Attackers also use AitM tactics for phishing attacks. In this case, the attacker’s fake web page collects the user identity. In the background, the fake page feeds the identity into Microsoft's valid webpage. This masks the attacker's presence and helps them steal session tokens so they can carry out future campaigns undetected.

Todyl’s threat report on the Söze Syndicate shows a prime example of this technique.

Initial access markets

For some attackers, the easiest way to obtain identities is to simply purchase them. Through initial access markets, bad actors can put the identities they’ve stolen up for sale. This lets them quickly profit from stolen identities without risking detection. It also reduces the amount of time they need to invest, making it appealing for opportunist attackers.

On the other side of the transaction, buying attackers don’t have to invest any time to steal credentials. Instead, they offset that cost with a focus on achieving larger goals like stealing data or installing ransomware. They can then use purchased identities attack the compromised organization through BEC, AT, ransomware, etc.

How MXDR Provides 24/7 ITDR

Organizations need ongoing visibility to watch for identity compromise and swift response to prevent credential theft and misuse. This is best accomplished through ITDR, but it requires significant investment and expertise to do so.

24/7 ITDR needs a full-time team of security experts to spot and stop potential identity threats. For budget-strapped MSPs and their SMBs clients, a 24/7 team with adequate security expertise is simply too expensive. So, how can these companies achieve the ITDR protection they need to prevent identity-based threats?

MXDR can answer that question by providing 24/7 security monitoring, investigation, and expertise as-a-Service. Just like an in-house security team, MXDR reviews log data, identifies threats, and acts accordingly on your behalf. Continuous detection coverage protects user identities, even outside working hours, and augmented response capabilities lead to faster containment and resolution.

Getting Under the Hood

MXDR uses the Todyl Security Platform to facilitate effective ITDR for your organization. By integrating with Microsoft 365, Todyl SIEM collects log information that helps catch identity compromises. It starts with Todyl's Anomaly Detection Framework.

The Anomaly Detection Framework is a machine learning algorithm that analyzes user behavioral analytics. It finds changes in account activities that may indicate an identity is at risk. As a result, MXDR can quickly determine the validity of an identity threat and act accordingly.

MXDR delivers even stronger protections through Todyl SOAR. SOAR provides prebuilt response playbooks and actions that automatically stop identity threats by revoking, disabling, or even deleting potentially compromised accounts. This prevents attackers from using stolen credentials to take over the account or later sell them.

Beyond immediately identity threats, MXDR constantly expands its ITDR capabilities by investigating the novel techniques and tactics used to target identities. The MXDR team uses this information to build new detections, playbooks, and other processes into Todyl for all partners. This “herd immunity” approach helps expand ITDR across the community and reduces attacks at a larger scale.

See Todyl MXDR and ITDR in Action

MXDR's proven track record for detecting and responding to identity threats keeps organizations safe from identity threats. Read how we’ve stopped active identity threats in our recent case study.