CrowdStrike Falcon Identity Threat Protection
Falcon Identity: identity and Active Directory protection. Credential theft detection, lateral movement, privilege escalation. Identity-based Zero Trust.

Key Features
- AD monitoring - real-time Active Directory visibility
- Credential theft detection - password theft detection
- Lateral movement prevention - blocking horizontal movement
- Privilege escalation detection - escalation detection
- Identity-based Zero Trust - every access verified
Table of Contents
What is Falcon Identity?
Falcon Identity Threat Protection is a Falcon platform module dedicated to identity protection - primarily Active Directory, but also Azure AD and other identity providers.
Why identity protection is critical:
- 80% of attacks use stolen credentials
- Lateral movement almost always goes through AD
- Ransomware first takes over Domain Admin
- Dwell time - attackers are in AD for weeks before attack
The Active Directory Problem
AD is the main attack target
[Initial Access] --> [Credential Theft] --> [Lateral Movement] --> [Domain Admin]
|
[Game Over]
Typical attack chain:
- Phishing → first endpoint compromised
- Mimikatz → credential dump from LSASS
- Pass-the-Hash → lateral movement to other servers
- Kerberoasting → service account credentials obtained
- DCSync → dump all passwords from DC
- Golden Ticket → persistence as Domain Admin
Traditional solutions are not enough
- SIEM - sees logs, doesn’t understand context
- EDR - protects endpoints, doesn’t understand AD
- PAM - controls access, doesn’t detect attacks
- AD auditing - generates too much noise
How does Falcon Identity work?
1. Real-time AD Visibility
Falcon monitors Active Directory without installation on Domain Controllers:
[Domain Controllers] <-- Monitor --> [Falcon Identity]
| |
[Replication traffic] [Analysis & Detection]
| |
[Auth events] [Alerts & Response]
Monitored events:
- Authentication (NTLM, Kerberos)
- Group membership changes
- Privilege assignments
- Service account activity
- Replication traffic
2. Credential Theft Detection
Detecting various credential theft techniques:
LSASS Access:
- Mimikatz
- ProcDump
- Custom credential dumpers
Kerberos Attacks:
- Kerberoasting
- AS-REP Roasting
- Golden/Silver Ticket
Pass-the-X:
- Pass-the-Hash
- Pass-the-Ticket
- Overpass-the-Hash
3. Lateral Movement Detection
Detecting horizontal movement:
[Workstation A] --> [Workstation B] --> [Server C] --> [Domain Controller]
| | | |
ALERT ALERT ALERT CRITICAL
"Unusual "Admin "First "DCSync
RDP source" credentials access detected"
from to DC"
workstation"
Detected techniques:
- RDP/SMB/WinRM from unusual sources
- Service account used interactively
- Admin credentials on workstations
- Unusual authentication patterns
4. Honey Tokens
Decoys to detect attackers:
Honey Users: False AD accounts that shouldn’t be used:
cn=svc_backup_admin, ...
(Looks like service account, but is a decoy)
Any use attempt = alert.
Honey Credentials: False credentials in LSASS memory:
- Attacker dumps credentials
- Tries to use honey credential
- Immediate alert
5. Zero Trust Enforcement
Identity-based access decisions:
Risk-based Authentication:
- User risk score (behavioral analysis)
- Device risk score (Falcon Agent)
- Location/time anomalies
- Authentication pattern changes
Conditional Access:
IF user_risk = high OR device_risk = high
THEN require MFA + limit access
Integrations
Microsoft
- Active Directory (on-prem)
- Azure AD / Entra ID
- Microsoft 365
Identity Providers
- Okta
- Ping Identity
- OneLogin
PAM Solutions
- CyberArk
- Delinea
- BeyondTrust
Falcon Identity vs Competition
| Feature | Falcon Identity | Microsoft Defender for Identity | Tenable.ad |
|---|---|---|---|
| Deployment | Agentless | Sensors on DCs | Agents |
| Detection | Real-time | Near real-time | Periodic |
| XDR Integration | Native | Microsoft ecosystem | Limited |
| Honey tokens | Yes | No | No |
| Zero Trust | Full | Limited | No |
Use Cases
Ransomware Prevention
Detecting lateral movement before encryption:
- Credential theft detection
- Lateral movement alerts
- DCSync prevention
- Automatic response
Insider Threat
Detecting malicious employee actions:
- Unusual access patterns
- Privilege abuse
- Data exfiltration indicators
Compliance
Meeting audit requirements:
- Privileged access monitoring
- Authentication logging
- Change tracking
Implementation
Requirements
- Windows Server 2012+ (Domain Controllers)
- Network access to DC replication traffic
- Falcon Insight on endpoints (optional, but recommended)
Deployment
- Configuration in Falcon console
- Network setup (monitoring replication)
- Honey token deployment
- Policy configuration
- Integration with response playbooks
Implementation time: 1-2 weeks AD impact: Zero (no agents on DCs)
Inquire about CrowdStrike Falcon Identity Threat Protection
Contact your product specialist and get a custom quote.

Related Services
Our services supporting the implementation and management of this solution
Managed Endpoint Protection (EDR/XDR)
Cybersecurity
Every endpoint protected. Every alert analyzed. Ransomware blocked in 15 minutes.
Threat Intelligence
Cybersecurity
Know your enemy before they strike. Proactive defense powered by data.
Managed Detection & Response (MDR)
Cybersecurity
24/7 protection by experts, without building your own SOC.
Cloud Security Audit and Protection
Cybersecurity
Check AWS/Azure/GCP security before attackers find misconfigurations. CSPM + manual review.
From Our Knowledge Base
Articles related to this solution
Blocking the Device Code Flow in Microsoft Entra ID with Conditional Access
How to reduce the risk of Device Code Phishing? A practical guide to blocking the Device Code Flow in Microsoft Entra ID with Conditional Access — step by step, with pitfalls and validation.
Cyber threat landscape 2026: a report for Polish companies in the NIS2 era
Poland is the most digitally attacked EU country. Explore the 2026 cyber threat landscape in numbers, the three most dangerous attack vectors and the NIS2/KSC obligations for Polish companies.
Deepfake, vishing and CEO fraud: how to protect your company from AI-powered scams
A deepfake on a video call, voice cloning and AI-powered CEO fraud mean real losses in the millions. Learn how these scams work and the proven defenses, including second-channel verification.
Related Products
Other solutions you might be interested in
Aruba ClearPass
Aruba Networks
Aruba ClearPass: NAC platform with profiling of 70+ thousand device types. Zero Trust access control for users, BYOD, and IoT.
Barracuda CloudGen Firewall
Barracuda Networks
Barracuda CloudGen Firewall: next-gen firewall with SD-WAN. IPS, application control, VPN, threat protection. Appliance, virtual, cloud.
Barracuda Email Protection
Barracuda Networks
Barracuda Email Protection: AI-powered email security against phishing, ransomware, BEC and account takeover. Gateway + API for Microsoft 365 and Google.
Barracuda SecureEdge
Barracuda Networks
Barracuda SecureEdge: SASE platform combining SD-WAN with cloud security. Zero Trust, SWG, CASB, FWaaS. Protection for distributed workforce.
Want to Reduce IT Risk and Costs?
Book a free consultation - we respond within 24h
Or download free guide:
Download NIS2 Checklist