Detection Without Automated Response Fails: Lessons for Identity-First CTI

July 24, 2026

By Flare Product 

In the mid-2010s, endpoint security reached a breaking point. Malware volume grew nearly eightfold between 2010 and 2016. Ransomware campaigns like WannaCry and NotPetya exploited the gap between detection and manual response with devastating efficiency. The industry’s answer was EDR: push automated response as close to the point of attack as possible and close the gap to zero. It worked. 

According to the 2024 Microsoft Digital Defense Report, over 90% of attacks that progressed to the ransom stage now originate from unmanaged devices, the systems that fall outside the EDR shield. The lesson was clear: detection without automated response is not defense; it is observation. Identity security is now at the same inflection point. Fifty million breached identities are traded weekly across Telegram and dark web channels. Stolen credentials appear on criminal markets within minutes of theft. And the defenses most organizations rely on (IAM and ITDR) act at or after authentication, well after the credential has been stolen, sold, and acquired by an attacker. 

The identity perimeter needs what the network perimeter got a decade ago: automated response that acts early enough to matter.

Flare CTA Block Preview

Identity-First Threat Intelligence

Detect and Remediate Stolen Credentials Before Attackers Log In

50 million breached identities are traded weekly. Stolen credentials are operationalized within 48 hours. MFA is routinely bypassed with session tokens. Flare’s identity-first CTI continuously monitors criminal marketplaces and infostealer logs to detect your exposed credentials at the point of theft, enabling automated response before attackers ever reach your authentication layer.

Continuous monitoring of dark web markets, Telegram channels, and infostealer logs for your exposed credentials
Automated remediation workflows that act at the point of exposure
Start Free Trial

The State of the Identity Perimeter

Identity has always been under attack. But today’s numbers show significant increases in both the volume and speed of identity attacks, reflecting a shift in how stolen identities are used and valued, particularly corporate credentials.

The volume is staggering. As of October 2025, our research shows that 50 million breached identities are traded weekly across Telegram and dark web channels

Our research also shows that initial access brokers monetize credentials and active session tokens within 48 hours of theft

The ecosystem is industrialized. That volume and speed has driven the establishment of a cybercrime ecosystem and economy built to facilitate the exchange of stolen identities. In addition to established “trade routes” and brokers that handle this volume with speed, Malware-as-a-Service (MaaS) for infostealers offers subscriptions around $150/month that enable unsophisticated threat actors to use stolen identity information in their attacks. This lets less sophisticated threat actors use stolen identity information in their attacks. 

Corporate credentials are increasingly in the mix. This bigger, faster flow of industrialized stolen identity information includes more corporate information. Flare’s research shows that enterprise infections in infostealer logs have grown from approximately 6% (January 2024) to about 14% (November 2025) and continue to accelerate.

The result of this new threat environment is a change in the use of stolen identities by threat actors. While stolen identities were once primarily associated with consumer account takeover, they’re increasingly being used to gain access to enterprise environments.

Verizon’s 2026 Data Breach Investigations Report (DBIR) bears this out:

  • 73% of ransomware victims had an associated infostealer or credential leak event in the prior year; of those, 50% had that event within 95 days of the attack.
  • Ransomware increased to 48% of all breaches (up from 44%).
  • Credential abuse appears in 39% of breaches when measured across the full attack chain, not just initial access.

Threat Actors Found Their Way Around MFA

Multi-factor authentication (MFA), widely positioned as the answer to stolen credentials, has not delivered on that promise.

First, MFA adoption has been uneven, not universal, years after its introduction. The 2024 campaign targeting Snowflake customer accounts illustrates this. Credentials stolen via infostealer malware years earlier had never been rotated and the accounts they accessed had no MFA enforced. Threat actors simply logged in.

More importantly, threat actors have already found ways around MFA. Increasingly, we see cookies and session keys that can be used to bypass MFA in infostealer logs. With a stolen session, the attacker assumes the role of the user. There is no log-in event to trigger an MFA challenge, there is nothing that would trigger an alert at all, the session looks legitimate.

The identity perimeter isn’t under pressure; it’s being breached at industrial scale. If existing protections aren’t meeting the challenge, what can? To answer that, we can look back to the classic perimeter and how the industry responded to increasing attacks that outstripped its existing defenses.

Key Lessons from EDR and the Classic Perimeter

When the industry started moving to EDR in the mid-2010s it was because endpoint attacks had increased in speed, sophistication, and volume such that the existing endpoint protections were simply outstripped. 

Attackers were increasingly able to move past and ignore defenses like antivirus and firewalls. These technologies, with their focus on detection, were good at alerting as to what was going on but not at stopping it. These technologies offered some limited response capabilities but overall response was left to human responders and other technologies. This handoff created a gap between detection and response where action consistently came too late in the attack chain. This also led to classic “whack-a-mole” scenarios, where each individual attack had to be handled separately, compounding the burden and complicating response.

The growth of malware from 2010 through 2016 shows how the problem unfolded, and displayed a similar trajectory to what we’re seeing now around identity attacks. A look at the historical data for malware from AV-TEST shows a clear, significant jump in both the volume of total and new malware between 2010 and 2016: from 44,571,209 total malware in December 2010 to 343,781,503 in December 2016: a nearly eight-fold increase. For context, this outpaced the overall internet traffic growth rate by 1.5x over the same time period.

Ransomware in particular exploited this gap. It industrialized malware from an end goal into a component of a multi-stage attack chain. The gap between detection and response became a crucial time where attackers thrived and moved unnoticed to the final, damaging goal of their attacks: the encryption of data for extortion.

The parallel between EDR and the identity perimeter isn’t cosmetic: it’s structural. Which raises the question: where is the automated response layer for identity, and where in the attack chain is it most effective? 

Automating Identity Response Effectively

Automating response isn’t a new idea: it’s at the heart of the development of EDR and present in its successor Extended Detection and Response (XDR). It’s present in some, but not all, identity protection technologies. But a key question when talking about automated response and its effectiveness is: when does response happen in the attack chain?

The EDR Model: Closing the Gap to Zero

One of the goals of EDR/XDR is to detect and stop attacks before they do harm. The gap between detection and response closes to zero. EDR/XDR does not protect a single endpoint; it covers as many potential targets in an environment as possible with the same level of protection.

EDR/XDR works, which is exactly why most successful attacks now happen outside its shield.

Applying the Model to Identity

Truly automating response effectively means pushing that automated response as far up the attack chain as possible. It also means spreading that umbrella of protection as widely as possible to prevent the demonstrated risks of systems falling outside coverage.

Fortunately, these two challenges can be solved simultaneously. If detection and automated response are placed early enough in the attack chain (closer to when identities are stolen than when they are used), a single response action earlier in the chain can be broader, faster, and more effective than any number of actions taken later.

The approach that enables this shift already exists: Identity-First Cyber Threat Intelligence (CTI).

How Identity-First CTI Enables More Effective Automated Responses

Cyber threat intelligence (CTI) transforms raw threat data into actionable context for defense decisions. Traditionally, CTI optimized for visibility: more sources, more alerts, and more coverage. This led to a data overload.

Identity-first CTI continuously discovers, contextualizes, and enables remediation of exposed identities before attackers can operationalize them. The scope narrows to the signal and ignores the noise. 

Why CTI Works for Identity

In the industrialized cybercrime industry around stolen identities, Identity-first CTI is most effective because it continuously monitors marketplaces for stolen identity information being sold. Detection and response at this point in the attack chain is where the exposure can be identified and acted on most quickly and efficiently: when information is being traded rather than being used in attacks.

Identity-first CTI offers three practical advantages for supporting automated response:

  • A single response can neutralize multiple attacks: A single exposure, like a single set of stolen credentials, can translate into multiple downstream attacks. Detection and response early in the attack chain like this makes it possible for a single response action to be effective against multiple attacks. Faster detection and response earlier in the attack chain can reduce the damage a single exposure could cause. Catching it early in the attack chain means one response action can neutralize all of them before the damage multiplies.
  • More time to validate: Acting at the point of exposure rather than the point of use gives defenders more time to confirm findings and validate the appropriate response. Fewer, higher-confidence actions reduce the burden on security teams.
  • Reduced false positive risk: Defenders know that speed and overwhelming volume increase the risks of false positives. The risk of false positives is a major concern that drags on the adoption of automated response and limits its acceptance and uptake. 

Identity Protection’s Role in the Security Ecosystem

The new perimeter doesn’t replace the classic one. The goal of attackers targeting identity is to log into networks and systems rather than breaking in. Identity-first CTI isn’t a standalone solution, as it joins other protections we’ve come to rely on, like XDR and other classic perimeter protections.

New technologies augmenting existing ones is a familiar story in cybersecurity. We’ve seen this with other protection technologies: firewalls didn’t replace antivirus. Firewalls on endpoints didn’t replace antivirus or firewalls at the perimeter. New technologies augmenting and working with existing ones is the practical demonstration of “defense in depth.”

Industry Acquisitions Validate the Shift

This means that we can look to trends in the security industry for signs of where attackers have been moving and defenders are going to meet them. A look at recent developments in cybersecurity validates and emphasizes that identity is the new perimeter and that protecting it is a new priority and joins the existing, necessary, and established technologies.

Acquisitions:

  • CrowdStrike acquired Adaptive Shield (November 2024), adding SaaS Security Posture Management (SSPM) capabilities to its platform.
  • Palo Alto Networks completed its acquisition of CyberArk (February 2026), adding identity security and privileged access management for human, machine, and AI identities to its platform.
  • ServiceNow completed its acquisition of Veza (March 2026), adding identity security, authorization intelligence, and identity relationship mapping capabilities to its platform.

These acquisitions reflect an industry shift. Identity has become a strategic control plane for modern security architectures, and vendors across the industry are investing accordingly.

Applying Lessons Learned from EDR to Identity

EDR taught the industry that detection without automated response is not defense. The same lesson now applies to identity. The structural parallels are clear: industrialized attack volume that outstrips existing defenses, a gap between detection and response that attackers exploit, and the need for automation that acts early enough in the attack chain to make a difference.

For identity, “early enough” means acting at the point of credential theft and exposure, not at the point of authentication. Identity-first CTI enables this by continuously monitoring the criminal markets where stolen credentials are traded, giving defenders the upstream intelligence they need to automate response before attackers ever log in.

This does not replace IAM, ITDR, or XDR. It feeds them. And it joins them as part of the defense-in-depth strategy that modern networks require. The way to best protect the classic perimeter is to protect the new one: placing response when and where it can actually stop the attack.

Flare CTA Block Preview

Identity-First Threat Intelligence

Detect and Remediate Stolen Credentials Before Attackers Log In

50 million breached identities are traded weekly. Stolen credentials are operationalized within 48 hours. MFA is routinely bypassed with session tokens. Flare’s identity-first CTI continuously monitors criminal marketplaces and infostealer logs to detect your exposed credentials at the point of theft, enabling automated response before attackers ever reach your authentication layer.

Continuous monitoring of dark web markets, Telegram channels, and infostealer logs for your exposed credentials
Automated remediation workflows that act at the point of exposure
Start Free Trial
Share article

Related Content

View All
07.23.2026

Impact Analysis of Ransomware Attacks on EMEA Healthcare

07.21.2026

NULLZEREPTOOL: Inside a Telegram-Controlled DDoS and Multi-Function Attack Framework

07.20.2026

Strengthening Our Commitment to Responsible Threat Intelligence