ITDR Enrichment Engine

What Is Blackpoint’s Enrichment Engine for ITDR?

Blackpoint’s Enrichment Engine is an ITDR capability that enriches Microsoft 365 logins in real time across multiple signals, including autonomous sources, user agents, VPNs and proxies, geolocation, and connected applications. This enrichment helps Blackpoint’s Security Operations Center (SOC) detect threats hiding within normal traffic.

Who Is It For?

The Enrichment Engine is designed for MSPs whose clients are at risk of being compromised through stolen Microsoft 365 credentials rather than endpoints, covering the identity layer that most MDR tools do not protect.

What Does It Include?

  • Autonomous sources: Flags logins from infrastructure that should not be there.
  • User agents: Detects risky or abnormal agents at login.
  • VPN and proxy detection: Unmasks anonymizing services used to conceal credential misuse.
  • Geolocation: Flags logins occurring outside a user’s normal baseline.
  • Application monitoring: Detects unauthorized applications.
  • Multi-event detection: Identifies slow, staged attacks that single-event logic misses, extending this protection into SIEM logs.
  • And more.

Why Do MSPs Choose It?

In 2025, Blackpoint’s SOC disrupted compromised cloud accounts in an average of 18 minutes, stopping identity attacks before they became breaches and helping MSPs demonstrate that they protect clients against identity-based threats.

Download Now
DATE PUBLISHEDSeptember 10, 2026
AUTHORBlackpoint Cyber

The 2AM Test

Executive Guide
Most MDR evaluations focus on dashboards, not what a provider actually does when something is live. Learn the four questions that matter more than the demo: authority, speed, surface coverage, and proof.
*88–91% of ransomware attacks land outside business hours

GET YOUR COPY