Falcon Identity Threat Detection

CrowdStrike Falcon Identity Threat Detection (ITD) provides AD Security visibility across all account types with insights and analytics, and detects identity-based attacks or anomalies by comparing live authentication traffic against basic behaviors and attack patterns.

Fabricantes: CrowdStrike
Category: Rede/Segurança
Learn more about Falcon Identity Threat Detection

Request a Quote

What is Falcon Identity Threat Detection?

CrowdStrike Falcon Identity Threat Detection (ITD) provides AD Security visibility across all account types with insights and analytics, and detects identity-based attacks or anomalies by comparing live authentication traffic against basic behaviors and attack patterns.

BENEFITS

LEARN WHAT ACCOUNTS ARE DOING BEFORE BREACHES HAPPEN

INSIGHTS AND ANALYTICS FOR ALL CREDENTIALS

Falcon Identity Threat Detection allows you to see all service and privileged accounts on your network and cloud with full credential profiles and weak authentication discovery across all domains. Analyze each domain in your organization for potential vulnerability of stale credentials, weak or stale passwords, see any service connections and weak authentication protocols in use.

DETECT LATERAL MOVEMENT FOR AUTHENTICATED ACCOUNTS

Falcon Identity Threat Detection monitors domain controllers on-premises or in the cloud (via API) to see all authentication traffic. Falcon ITD creates a baseline for all entities and compares behavior with unusual lateral movement, Golden Ticket attacks, Mimikatz traffic patterns, and other related threats. Falcon ITD can help you see privilege escalation and anomalous service account activity.

AD SECURITY WITHOUT USING LOGS

Falcon Identity Threat Detection reduces detection time by viewing live authentication traffic, which speeds up the location and resolution of incidents. View real-time events and potential incidents during authentication by rogue users of any type. Falcon ITD offers curated traffic feeds to enrich the "what" of identity protection events with the "who" of credential identification.

FEATURES OF FALCON IDENTITY THREAT DETECTION

AUTOMATED THREAT DETECTION

Provides continuous multi-directory visibility into the status, scope, and impact of access privileges for identities in Microsoft Active Directory (AD) Azure AD and single sign-on (SSO) solutions in the cloud

Automatically classifies identities into hybrid (identities that are on-premises and in the AD cloud) and cloud-only (identities that reside only in Azure AD) with risk scores

Detects lateral movement and anomalous traffic in real time by any user or service account

SIMPLE CONTROLS - NO SCRIPTING REQUIRED

Falcon Identity Threat Detection provides simple point-and-click functionality to discover all the credentials in your environment and your security posture on managed or unmanaged devices, as well as service account activity.

Provides continuous assessment of security and incidents related to identity threats with easy search capabilities in Threat Hunter, enabling AD staff or security analysts to quickly find issues and investigate. Threat Hunter also receives human information (incident resolution) to create incident records for troubleshooting and incident response (IR) teams

Discovers recognition (e.g., LDAP, BloodHound, SharpHound, credential compromise attacks), lateral movement (e.g., RDP, mimikatz tool, unusual endpoint usage, unusual service logins, etc.), and persistence (e.g., Golden Ticket attack) with advanced analytics and patented machine learning technology

Accelerates security investigations using intuitive threat hunting, with predefined search criteria, e.g. authentication events, unencrypted protocols, user roles, IP reputation, risk scoring, and more – and with best practice advice

COVERAGE MITER ATT & CK

Falcon ITD maps against the MITER ATT & CK framework to help you build more complete security coverage. Falcon ITD offers detections for many subgroups of these higher-level techniques:

Recognition, execution, persistence, privilege escalation

Defense evasion, credential access, discovery, lateral movement

Collection, Command and Control, Impact, Removal

System Requirements:

CPU: 1.8 GHz dual core processor

RAM: 2 GB

HDD/SSD: 50 GB of free space on main drive

Operating system: Microsoft Windows 10, Microsoft Windows 8 32-bit, Microsoft Windows 7 32-bit, and Microsoft Windows Vista 32-bit

Resolution: 1024×768

Supported Operating Systems

Mac OS X 10.5x (Leopard), Mac OS X 10.6 (Snow Leopard), Mac OS X 10.7 (Lion), Mac OS X 10.7 (Mountain Lion), OS X 10.9 (Mavericks), and Mac OS X 10.10 (Yosemite)

Hardware requirements

Memory - 1 GB RAM and more

Free disk space - 50 MB

System type - 32-bit and 64-bit OS

You don't know what software you need or you haven't found what you were looking for?

You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.