ITDR: Sample Capabilities List
Identity Data Ingestion
Example Capability
Auth source import (HR data)
Identity provider importation
User profile data including permissions import
SaaS, cloud and on-premises systems import
SCIM support
Flat file support
Native API support
Extensible
OOTB connectors / accelerators
Activity Data Ingestion
Example Capability
SaaS systems import
CSP systems import
IDP import
Flat file support
Native API support
Extensible
Network activity
Visibility
Example Capability
Data correlation and normalization
Single view of identities, permissions and activity
Overlay of risk and threat
Both real and potential
● Linkages between session and application activity
● Linkages between activity data and attack frameworks
Overlay of theoretical threat from attack trees
Overlay of Cyber Threat Intelligence
Detection
Example Capability
Rule and policy creation
Rule triggering
Automated monitoring
Continual compliance
Baseline behaviour creation
Behaviour deviation triggers
Response/Remediation
Example Capability
Email notifications
Slack integration
Workflow and ticket management integration
Webhooks and APIs