Sophos Launches Identity Threat Detection and Response Capabilities for Comprehensive Identity Protection
Sophos Identity Threat Detection and Response (ITDR) has been launched by Sophos, marking a significant milestone following the Secureworks acquisition. This new capability for Sophos XDR and MDR helps organizations swiftly detect, investigate, and remediate identity-based attacks. The integration strengthens Sophos' security operations (SecOps) portfolio, providing comprehensive identity protection for over 600,000 customers worldwide.
Key Takeaways:
- The Sophos X-Ops Counter Threat Unit (CTU) observed a 106% increase in stolen credentials available for sale on the dark web between June 2024 and June 2025.
- Compromised credentials were the top root cause of attacks for the second consecutive year, with 56% of incidents involving attackers using valid accounts to access remote services.
- Identity-based threats are now among the fastest-growing attack vectors globally, with complex identity and access management systems often leaving security gaps.
- Sophos ITDR continuously monitors customer environments for misconfigurations, exposed credentials, and risky user behavior, detecting and defending against all known MITRE ATT&CK Credential Access techniques through more than 80 cloud identity posture checks, AI-driven analytics, and dark web intelligence.
- ITDR's key capabilities include Identity Catalog & Dashboard, Continuous Assessments, Compromised Credential & Dark Web Monitoring, User Behavior Analytics (UEBA), and Automated Response Playbooks.
- The integration seamlessly links ITDR with Sophos XDR and MDR, automatically generating cases when identity threats are detected, allowing security analysts to investigate and take response actions, accelerating remediation and reducing organizational risk.
Statistics:
- 106% increase in stolen credentials available for sale on the dark web between June 2024 and June 2025.
- 56% of incidents involving attackers using valid accounts to access remote services were the top root cause of attacks for the second consecutive year.
- Over 600,000 Sophos customers worldwide are now receiving comprehensive identity protection through Sophos ITDR and the integrated Sophos Central platform.
Sources:
- The announcement by Sophos Team, June 2025,
- The Sophos Active Adversary Report, 2025,
- Quote from Rob Harrison, SVP, Product Management, Sophos, June 2025