← All 186 courses
SEC-209 Security

Identity Threat Detection & Response (ITDR)

Detect and contain attacks against identity itself, where most modern intrusions now begin. Learners map the hybrid directory attack surface, build detections for token theft, session abuse and MFA fatigue, graph privileged escalation paths, and assemble identity telemetry across IdP, directory and endpoint. Containment is rehearsed end to end: session revocation, factor reset and key rotation with a measured blast radius.

B4Professional
6modules
42skill atoms
2role journeys
Curriculum

What this course covers.

6 modules, 42 named skill atoms. Expand any module to see them.

1Identity Attack Surface7 skill atoms
on-prem AD and Entra ID hybrid trustlegacy authentication protocols still enabledservice accounts and delegationfederation trust and token signing key exposuredirectory ACL and privilege sprawlguest and B2B identitiesnon-human identity growth
2Token Theft & Session Abuse7 skill atoms
stolen session cookie indicatorsimpossible travel and device mismatch signalstoken replay from unexpected ASN or clientadversary-in-the-middle phishing patternsdevice code and consent phishing indicatorsrefresh token lifetime and revocation lagcontinuous access evaluation
3MFA & Factor Strength7 skill atoms
MFA fatigue and push bombing detectionnumber matching and prompt contextphishing-resistant FIDO2 and certificate-based authenticationfallback factors as the weak linknew factor registration as a high-signal eventconditional access policy gapsbreak-glass account monitoring
4Privilege Escalation Paths7 skill atoms
tiered administration modelattack path graphing across the directoryshadow admin and nested group discoveryrole assignment and PIM activation monitoringKerberos delegation misconfigurationcloud role assumption chainsmeasuring path reduction over time
5Identity Telemetry & Coverage7 skill atoms
IdP sign-in and audit logsdomain controller and directory change eventsEDR correlation with identity eventsUEBA baselining and false positive costcoverage against ATT&CK credential access techniquesenrichment with user, device and risk contextgap analysis by log source
6Containment & Recovery7 skill atoms
revoke sessions and refresh tokensdisable vs contain trade-offcredential and factor reset sequencingrotating signing keys and service account secretsscoping blast radius across SaaS and cloudcommunicating with the affected userpost-incident hardening and detection backlog
Where it fits

SEC-209 in the role journeys.

This course appears in 2 of our 45 role journeys. Here is what a learner takes immediately before and after it in each.

SOC Analyst

Professional stage
SEC-206SEC-209SEC-406

IAM Engineer

Professional stage
SEC-202SEC-209SEC-205

Roles this course serves

The capability ladder

This course is authored to band B4.

Every course we run is written to one rung of the CASI ladder, so a plan can be assembled to take a team from where they are to where they need to be.

What do B1–B6 mean?The CASI Capability Ladder — click to expand

Every course targets a band on the CASI Capability Ladder — our six-band proficiency scale, anchored to open standards (O*NET, ESCO, NICE, NIST AI RMF, Bloom's). A band tells you how deep a course goes, and what evidence proves it.

What the learner can doTypical evidence
B1
AwareUnderstands concepts and vocabulary; uses tools with guidance
Knowledge checks
B2
FoundationPerforms standard tasks correctly in familiar contexts
Guided labs, autograded exercises
B3
PractitionerDelivers complete pieces of work independently
Scenario labs, proctored hands-on exams
B4
ProfessionalHandles production-grade complexity, trade-offs and failure modes
Break-fix drills, design defenses
B5
AdvancedEngineers systems end-to-end under constraints; leads others
Rubric-scored capstones, vivas
B6
ExpertSets direction; recognised authority across teams
Portfolio + panel evaluation

A note on B6. Courses in this catalog target B1–B5. B6 is not taught — it is recognised, through a portfolio and a panel, once someone is setting direction for others. Every journey here is built to land a learner at B5.

Next step

Run SEC-209 for your team.

This course runs at several lengths depending on how deep you need to go and how much of it your people already have. Tell us who is being trained and we will scope it.

Add it to a training plan Talk to our team Check your team’s level free