Identity and Email Threat Detection Powered by CrowdStrike Falcon
Brian Long
Introduction
Attackers increasingly log in instead of breaking in. With a phished password or a user worn down by repeated MFA prompts, they can walk past defenses built to stop malware. Identity threat detection and response (ITDR) watches how accounts are actually used, so a stolen login gets noticed before it does damage.
The attack path that starts with a convincing email and a stolen password is watched end to end: the sign-in, what happens in the mailbox, and what happens on your computers, correlated and cut off before it spreads. Identity and email threat detection is included in every Cyber Protection Package, covering Active Directory, Microsoft Entra ID, and Microsoft 365. In the Cyber Protection Package with CrowdStrike Falcon, it’s delivered by Synapses Technologies and powered by CrowdStrike Falcon Identity Protection.
- Monitors identity activity in real time: Sign-ins, access, and account changes.
- Detects abnormal behavior: Logins from unusual places or at unusual times, and access that doesn’t fit the user.
- Watches privilege changes: Flags new administrators and unusual use of powerful accounts.
- Helps stop attackers moving through your network: Catches the lateral movement and privilege abuse that follow a stolen login.
- Watches Microsoft 365 email activity: Flags signs of a compromised mailbox, like new forwarding rules and unusual admin changes.
- Correlates identity, email, and endpoint: A suspicious sign-in, a new mailbox rule, and odd activity on a laptop are seen as one attack, not three separate alerts.
- Works with your existing MFA: Adds a layer on top of multi-factor authentication instead of replacing it.
Identity protection is especially important for:
- Financial services, accounting, legal, healthcare, and education organizations
- Businesses that move money by wire or ACH, or handle sensitive client data
- Any business worried about stolen passwords or someone misusing their access
Already using MFA? ITDR is the next step. It catches the attacks that get past MFA.
- Setup: We connect identity protection to your directory and sign-in systems.
- 24/7 monitoring: Suspicious identity activity is investigated around the clock alongside your endpoint alerts.
- Response: We act on confirmed threats, like locking a compromised account and forcing a password reset, and explain what happened.
Part of the Cyber Protection Package
Identity protection works alongside managed endpoint protection in our Cyber Protection Package, and pairs with 1Password password management to keep credentials from being stolen in the first place.
Not sure how exposed your accounts are? Contact us and schedule a free identity risk review.
CrowdStrike and Falcon are trademarks of CrowdStrike, Inc.