Firewalls, endpoint protection, and monitoring tools are still important, but they’re no longer where most attacks start…identity.
Today’s attackers don’t break in. They log in with your identity.
Stolen credentials, abused service accounts, and over-permissioned users have become the easiest path into modern environments. That shift is exactly why Identity Threat Detection and Response (ITDR) is gaining so much attention.
What is ITDR?
ITDR focuses on detecting and stopping threats that abuse identities instead of systems.
Rather than asking “Is this device compromised?” ITDR asks a more relevant question: “Does this identity’s behavior make sense?”
ITDR looks at the behavior of:
- User accounts
- Administrator privileges
- Service accounts and API keys
- Cloud and SaaS identities
Why Traditional Security Misses Identity-Based Attacks
Most security tools were built for a different era. They’re good at spotting malware, suspicious files, or known attack signatures. But identity-based attacks often look legitimate on the surface:
- A real username
- A valid password
- A successful login
By the time something looks “malicious,” the attacker may already have access to sensitive systems or data. ITDR fills this gap by watching how identities behave over time, not just whether access was granted.
To understand identity-based attacks in more detail, what they look like, how they happen, and how organizations can protect themselves, we recently hosted a webinar with the CEO & Co-Founder of Petra Security, Cooper Edmunds. It’s a great resource to see these threats in action and learn more about the solutions General Informatics delivers. You can watch it here.
How ITDR Complements Your Security Strategy
ITDR doesn’t replace IAM, PAM, or MFA; it amplifies them by adding detection and response where it’s most needed.
Think of it this way:
IAM
Identity and Access Management
Controls who can access
PAM
Privileged Access Management
Controls who should have access
MFA
Multi-Factor Authentication
Controls who proves their identity when accessing
ITDR
Identity Threat Detection and Response
Together, they create a stronger, more realistic defense.
Real-World Impact
Identity abuse isn’t hypothetical. Stolen accounts, over-permissioned admin accounts, and misused service tokens are increasingly how attackers breach organizations. These incidents can lead to operational downtime, compliance violations, data exposure, and lost customer trust.
More than two-thirds of organizations worldwide report a rise in identity-based security incidents, and many can’t detect or respond until attackers have already established a foothold. Nearly half of businesses see these attacks making up over 40% of their incidents, and the consequences impact operations, trust, and the bottom line. (BetaNews)
General Informatics' Approach
General Informatics helps organizations implement ITDR as a practical, ongoing capability by combining our strategic expertise with advanced identity-focused security solutions made possible through our work with specialized partners, including organizations like Petra Security.
This approach provides:
- Deep visibility into identity activity, not just logs – so suspicious access patterns don’t go unnoticed.
- Contextual signals that separate normal use from risky behavior, reducing noise and focusing attention where it matters.
- Rapid response workflows, so threats are contained and mitigated quickly.
- Actionable insights for business teams, translating technical alerts into understandable steps aligned with operational and compliance priorities.
Most importantly, General Informatics makes these capabilities accessible and manageable for organizations without requiring them to build complex internal ITDR programs from scratch.
What is Petra Security?
Petra Security is a cybersecurity company that specializes in identity-focused threat detection and response solutions. Their platform helps organizations detect suspicious behavior in user accounts, administrative accounts, and service accounts before it leads to major security incidents. Petra Security’s technology powers the identity monitoring and response capabilities that General Informatics integrates for its clients.
The Bottom Line
Identity has quietly become the center of gravity in modern cyberattacks. When attackers gain access through a trusted account, they don’t trigger alarms – they blend in. This reality is why Cybersecurity has shifted. The critical question for organizations is no longer “Can someone get in?” It’s “What happens if a trusted identity is abused?”
ITDR provides the missing layer of security: continuous visibility into how identities are being used, clear insight into suspicious behavior, and the ability to stop threats before they spread. Without it, many attacks go unnoticed until damage is already done.
Be on the lookout for our next blog, where we’ll pull back the curtain on the identity-based attacks that operate in plain sight — walking through how they start, what they look like once they’re inside an environment, and why they’re so easy to miss.
Think of General Informatics’ ITDR, powered through Petra Security, like a fire alarm, plus the fire department, plus a CSI forensics team: it doesn’t just tell you there’s a fire. It shows you where it started, what it touched, and helps you put it out safely. In the context of identity security, that means not only detecting when an account has been compromised, but also seeing which emails were read, which files were accessed, and what actions the attacker took. That context lets General Informatics respond quickly, contain the threat, and prevent further damage - all while understanding exactly what happened.
Cooper Edmunds, CEO & Founder, Petra Security
Ready to harden your identity-based defenses?
Book a no-pressure ITDR consult with our security experts.
Connect With Aaron
Get to Know
Aaron Lancaster
Aaron Lancaster is a security expert with a history of providing superior cybersecurity solutions to clients in numerous industries. With over 16 years of experience in the cybersecurity field, Aaron brings a wealth of knowledge and experience to the table and holds credentials that go beyond most in the industry.
In his current role as General Informatics’ Information Security Officer, Aaron is responsible for leading General Informatics’ Security Consulting Practice. Prior to being acquired by General Informatics, Aaron served as the CEO and Founder of 1 Ping Security. Aaron is a highly sought-after speaker and is often delivering keynotes to national security conferences. He has attained a vast amount of security certifications and holds leadership roles amongst multiple security associations and alliances.
In addition, Aaron is a veteran of the U.S. Army, having served as a scout reconnaissance helicopter pilot and Information Assurance Security Officer. He earned a Graduate Certificate in Pentesting and Ethical Hacking from the SANS Technology Institute and holds a Bachelor of Science degree in Aeronautics from Embry-Riddle Aeronautical University.