Attackers Move in Seconds Defenses Often Take Hours.

Blackpoint closes that gap. Our hybrid agentic approach to ITDR pairs an AI SOC – averaging under two minutes to containment, as fast as 21 seconds, with human analysts always available.

<2min
Average time to contain a compromised M365 or GWS account, in as little as 21 seconds
Blackpoint SOC Operations Data, 2026
80%+
Of credential-based breaches involve identity as the primary entry point
Palo Alto Unit 42 Incident Response Report, 2026
$2.77B
In reported losses from business email compromise in 2024
FBI IC3 Annual Report, 2024
29min
Average attacker breakout time from initial access to lateral movement
CrowdStrike Global Threat Report, 2026
The Problem

Your Clients’ Identities Are the Attack Surface

Attackers figured out that credentials are faster than malware. Stolen login information gets them into cloud environments, email accounts, and financial systems, and it all looks like legitimate access. No malware. No file to flag.

A compromised identity is a fast path to serious damage. Attackers use stolen credentials to gain access to sensitive data, redirect payments, impersonate executives, and more. And it’s often too late before anyone notices.

Alerts sitting in a queue give attackers time they should not have. Identity threats need to be caught and contained in the identity layer, where the attack actually lives, not handed off and waiting.

29m
Average attacker breakout time
CrowdStrike Global Threat Report, 2025
#1
Credential misuse was the leading cause of breaches in 2025
Verizon 2025 Data Breach Investigations Report
90%
Of incident investigations involved identity weakness as a key factor in 2025
Palo Alto Unit 42 Global Incident Response Report, 2026
How It Works

ITDR: Identity Threat Containment at Machine Speed

The AI SOC Agent detects threats, evaluates behavioral signals against trained threat patterns, and acts only when confidence thresholds are met. When thresholds are met, it suspends compromised accounts, terminates active sessions, and forces password resets in as little as 21 seconds, with an average containment time of under two minutes. Every action outside those defined boundaries routes to a human SOC analyst, along with the Agent’s full reasoning. The Agent was trained on over a decade of real SOC data and validated against human analyst judgment before autonomous action was ever enabled.

01
Continuous

Continuous Monitoring

The AI SOC Agent monitors identity signals across cloud environments, correlating behaviors like impossible travel, anomalous access hours, off-baseline application activity, and known attacker TTPs against a model trained on more than a decade of real SOC decisions.

02
Confidence-Led

Confidence-Led Action

High-confidence threats trigger immediate autonomous action, no ticket, no approval queue. Everything below the confidence threshold routes instantly to a human SOC analyst with the Agent’s full reasoning. Acts on certainty, routes on doubt.

03
Contained

Threat Contained in <2 Minutes

The AI SOC Agent suspends the account, forces a password reset, disrupts sessions, and logs a full summary. The human SOC is notified and a SOC analyst is available for questions.

See It In Action

Attackers Move in Seconds. Defenses Often Take Hours.

Blackpoint closes that gap. Walk through how our hybrid agentic ITDR detects and contains a real identity threat, inside CompassOne.

Detections Cloud & Identity MDR
2 Active Alerts
Modules
Security Posture Rating
Cloud Posture
Cloud & Identity MDR
SIEM
Vulnerability Mgmt
Explore
Detections
Policies
Reports
Cloud & Identity MDR
Monitor and manage cloud user accounts, with insights into activity, detections, and notifications.
New detection: Suspicious login from unknown location — john.doe@example.com
Just now
Top Detections by User
john.doe@example.com
14
m.smith@example.com
2
Global Login Activity — Past 7 Days
Approved location
Unapproved country
New device
1
VPN / Proxy Used
24
Protected Users
62
Cloud Notifications
Detections Cloud Response Detection Details
AI Enriched
Modules
Security Posture Rating
Cloud Posture
Cloud & Identity MDR
SIEM
Vulnerability Mgmt
Explore
Detections
Policies
Reports
AI
AI enriched — advanced behavioral analysis has been applied to this detection, delivering critical threat context to the SOC.
Event Login from Unapproved Country
User john.doe@
example.com
Connection example.com
Status Resolved
12:09 PM Detection triggered
12:09 PM AI analysis complete
12:11 PM Escalated
12:12 PM Resolved
Detection Summary
What We Detected
A sign-in to one employee’s Microsoft account came from an unfamiliar datacenter network and appeared as a first-time device and IP. The same session identifier was seen moments earlier on a different user from the same source, which points to stolen session or token use.
When It Happened
June 22, 2026 at 10:12 AM (UTC)
What This Means For You
This activity indicates a confirmed account compromise. Think of it like someone finding a copy of a key card and using it from a data center rather than a normal office or home location. Continued access from the same source right after the login suggests the attacker tried to keep using the account.
What We Did
  • Disabled the affected Microsoft account to stop further misuse
  • Notified your team and provided guidance on next steps
What You Should Do
  • Ensure multifactor authentication is enabled for the account (and ideally for all users)
  • If you use on-premises directory syncing, make sure the on-prem account is also disabled to prevent it from being re-enabled by sync
  • After remediation, re-enable the account only once secure and needed
Status
Resolved
Detections Cloud Response Incident Resolved
Threat Contained
Modules
Security Posture Rating
Cloud Posture
Cloud & Identity MDR
SIEM
Vulnerability Mgmt
Explore
Detections
Policies
Reports
Account Secured — Threat Neutralized
john.doe@example.com  ·  Resolved 12:12 PM
AI SOC Agent
Suspicious login detected — john.doe@example.com, unapproved country, VPN in use
12:09:00 PM
AI SOC Agent evaluates behavioral signals — confidence threshold met
12:09:04 PM
Account suspended — access blocked autonomously
12:09:11 PM
Active sessions terminated, password reset forced
12:09:18 PM
Human SOC notified — full incident summary logged
12:09:21 PM
Total Response Time
0:00.00
 
Full-Spectrum Coverage

What Blackpoint ITDR Delivers

From stopping account takeovers to blocking BEC before funds move, Blackpoint ITDR gives MSPs the coverage, speed, and platform context to protect every client identity, across every environment.

Prevent Account Takeover

Detects compromised credentials and anomalous logins. Isolates accounts early in the kill chain before the attacker establishes persistence or pivots to other environments.

Stop Business Email Compromise

Catches inbox rule creation, forwarding setup, and permission changes that signal a BEC event in progress, and shuts them down before funds are moved or clients are targeted.

Disrupt Session Hijacking

Identifies stolen session tokens and suspicious authentication patterns. Revokes access before the attacker can bypass MFA, access sensitive data, or spread across tenants.

Protection Across Tools You Depend On

Identity protection across all the tools your clients use to run their business.

Microsoft 365 Entra ID Exchange SharePoint OneDrive Teams Google Workspace Cisco Duo

Human Analysts On Your Side

SOC analysts are always available by phone to review a detection with you and answer any questions about an incident.

Security That Scales With You

As your client base grows, Blackpoint scales with it. No additional security headcount required on your end.

Why Blackpoint ITDR

Not All ITDR Is Created Equally

Blackpoint’s hybrid agentic approach to ITDR pairs an AI SOC with human analysts always available, so threats are contained at machine speed with human judgment always in the loop.

  Traditional Managed ITDR Blackpoint Agentic ITDR
Threat Detection ML or rule-based alerting, analyst reviews the queue Proprietary model trained on a decade of SOC data and intelligence Advantage
How Response Starts Alert generated, analyst triages, response initiated AI SOC Agent filters threats and acts autonomously within its guardrails Faster
Average Containment Time Minutes to hours depending on analyst availability and queue depth Under two minutes, and as little as 21 seconds for M365 and Google Workspace credential threats Fastest in class
Response at 2am Queued until analyst is available, dwell time increases significantly overnight AI SOC Agent operates identically at 2am as at 2pm, no queue, no delay Always on
Human Oversight Human-led throughout, analyst in the loop for every decision Human-in-the-loop approach and always available by phone for help Always Available
Platform Context Identity signals only, siloed from endpoint and posture data Cross-signal context from MDR, EDR, and Cloud Posture via CompassOne Platform advantage
CompassOne Platform

One Platform. More Context. Complete ITDR.

ITDR is not a standalone point solution, it is a native capability inside CompassOne, amplified by MDR context. When an identity threat occurs, ITDR pulls signal from across the platform: the devices involved, the applications touched, the vulnerabilities present on those assets.

You see the full picture of an incident, not just the identity signal. You have what you need to contain the threat and harden the environment before the next attempt.

Explore CompassOne
Identity Threat Detection
Active
Managed Detection and Response
Application Control
Vulnerability Management
Cloud Posture
SIEM
Security Posture Rating
From the Field

MSPs Who Trust Blackpoint ITDR

Over the past five years, Blackpoint’s SOC has been a trusted extension of our team. Every minute matters when protecting our clients from today’s cyber threats. The combination of Blackpoint’s AI and security analysts gives us confidence that we’re staying ahead of the growing volume of attacks.

Sean Furman
Sean Furman
President, STF Consulting
<2m
Average containment time How quickly the AI SOC Agent can detect and contain.
18m
An account disrupted every 18 minutes Across the Blackpoint customer base, on average, in 2025.
10+
Years of SOC data and intelligence Built into every detection and response decision the AI SOC Agent makes.

See Agentic ITDR Stop an Attack in 21 Seconds

No commitment. No configuration required. See exactly how Blackpoint protects your clients’ identities, live, with your own environment.

Request a Demo Or start your free trial
Frequently Asked Questions

Questions MSPs Ask Before Switching

What is ITDR and how is it different from MDR?

MDR focuses on endpoints and network activity, watching devices, detecting malware, and responding to endpoint-level threats. ITDR is the layer that catches attackers who bypass endpoints entirely by logging in with valid credentials. ITDR monitors identity signals: login behavior, session tokens, OAuth apps, inbox rules, permission changes. Blackpoint provides both, and when they are on the same platform, you get cross-signal context that standalone tools cannot match.

What does the AI SOC Agent do autonomously vs. what requires a human?

The AI SOC Agent detects threats, evaluates behavioral signals against trained threat patterns, and acts only when confidence thresholds are met. When thresholds are met, it suspends compromised accounts, terminates active sessions, and forces password resets in as little as 21 seconds, with an average containment time of under two minutes. Every action outside those defined boundaries routes to a human SOC analyst, along with the Agent’s full reasoning. The Agent was trained on over a decade of real SOC data and validated against human analyst judgment before autonomous action was ever enabled.

What happens if the AI SOC Agent acts on a false positive?

The process is the same as it would be with any SOC action. Contact Blackpoint directly and a SOC analyst will re-enable the account immediately. From there, the team reviews what triggered the action and tunes the model so the same false positive does not recur. Every autonomous action generates a full summary, so analysts have a record of what alerted it and every step it took. False positives feed directly into model improvement so the Agent gets more accurate with every correction a human analyst makes.

Which platforms does Blackpoint ITDR protect?

Blackpoint ITDR protects Microsoft 365 environments including Entra ID, Exchange, SharePoint, OneDrive, and Teams, as well as Google Workspace and Cisco Duo. The AI SOC Agent’s autonomous containment capability is currently active for M365 and Google Workspace credential threats. Human SOC analysts cover the full identity surface including Google Workspace and Duo. No premium Microsoft licensing is required.

Does Blackpoint ITDR require premium Microsoft licensing?

No. Blackpoint ITDR runs 24/7 identity monitoring and autonomous containment on standard Microsoft 365 licensing, no Microsoft 365 E5 or Entra ID P2 required. Clients with P2 or E5 get additional detection capabilities.

How is Blackpoint ITDR different from other identity security tools?

Most identity security tools detect threats and alert a human. Blackpoint’s hybrid agentic approach to ITDR detects, scores, and acts autonomously on high-confidence threats, with immediate human analyst backup for everything else. The AI model was built from real SOC decisions and validated against human analyst judgment before it was ever deployed in a client environment.