Skip to main content
Sweet Security
Runtime Detection and Response

Identity Threat Detection & Response (ITDR)

Detection of human and non-human identity and secret abuse

ITDR maintains an inventory of human and non-human identities (service accounts, IAM users, API keys, tokens) together with secrets and the context of how each is actually used at runtime. The platform monitors credentials, access patterns and privilege misuse, and turns baseline deviations, such as logins outside business hours or from unusual regions, cross-account role assumption or plaintext secret use, into incidents with full context. Cross-account session tracing in AWS reconstructs an attacker's lateral movement, and correlation with workload activity ties the identity event to what was actually executed on the machine.

Security

Enterprise-grade protection compliant with regulatory requirements and security standards

Performance

Fast deployment with minimal resource overhead

Support

Dedicated support from a certified partner

Integration

Easy integration with your existing infrastructure

Key features

  • An inventory of human and non-human identities and secrets with runtime context
  • Detection of plaintext secrets and of unmanaged, expired and excessive credentials
  • A context-aware baseline: alerts on access outside business hours or outside typical regions
  • Cross-account session tracing in multi-account AWS environments
  • Correlation of identity events from logs with workload activity from the sensor

Business benefits

  • Compromised service accounts and API keys caught before lateral movement
  • Visibility into non-human identities that usually sit outside IAM processes
  • Unused secrets and identities removed on the evidence of actual use, not guesswork
  • A record of identity use for access reviews (DORA, NIS2, SOC 2)
  • One platform for identities across AWS, Azure and Google Cloud
Sweet Security

Why Sweet Security?

Sweet Security is a Runtime CNAPP that detects and blocks attacks on cloud infrastructure, workloads, applications and AI agents while the attack is still under way. A lightweight eBPF sensor and cloud logs build a behavioral baseline of the environment, and a single detection engine correlates events across every layer to cut MTTR to minutes, according to Sweet Security data.

All products

Need Identity Threat Detection & Response (ITDR) in your organization?

As a certified Sweet Security partner, we'll help you deploy and configure the solution.

Book a free consultation