Features

Features

Identity threat detection and investigation

The identity security platform with the full picture

The identity security platform with the full picture

The identity security platform with the full picture

Attackers chain logins, group changes, and permissions across your systems. Icite connects all those dots and finds the threats.

Search⌘K
Home
Inquiries
Detection
Reports
Timeline
Identities
Recent
Which service accounts ha...
List all contractors whose...
Who accessed sensitive d...
Shared with you
Lumen Industries
m@lumen.com
HomeDeparting-employee exfiltration

Departing-employee exfiltration

This detection flags departing employees whose access shows a toxic combination of data-gathering across multiple platforms (Salesforce report export, GitHub repo clone, and heavy Google Drive access) in the run-up to their departure. Several members have been flagged.

Members
Member
Recurrence
First seen
Last seen
Classify
Sarah Chen
Open
May 5th,...
May 5th,...
Chris Fink
Open
May 5th,...
May 5th,...
Emily Grace
Open
May 5th,...
May 5th,...
Randall Savage
Lapsed
May 3rd ,...
May 3rd ,...
Triage

Situating narrative

This is a re-correlation of a previously triaged finding. The detection currently flags 200 active members; in current configuration data, the broader MFA-disabled, account-enabled population stands at 303 source records — 302 in Microsoft Entra ID and 1 in Okta Workforce. All 302 Entra accounts are active members (not guests), and none carries an admin flag in current configuration data. None of the MFA-disabled Entra accounts reaches a privileged Entra directory role, whether by direct assignment (confirmed in the prior triage) or by group-mediated assignment (confirmed now — the group-to-directory-role traversal returned zero paths). On compensating controls: the three Conditional Access policies that target "All users" are not enforcing — one is disabled and two are report-only — while every enabled CA policy is narrowly scoped to a single group or a 2-user include set, so no enforcing CA policy broadly covers this population.

Supporting facts

Current MFA-disabled + account-enabled population: 302 Entra ID, 1 Okta Workforce (303 total). This differs from the prior triage's 341 figure (which counted AWS IAM and Intune records); the current enabled set is smaller. Of the 302 MFA-disabled Entra accounts: 0 flagged as admin, 0 guests — all active members. Group-mediated privileged exposure: the traversal from MFA-disabled Entra accounts through group membership to a directory-role assignment returned no paths. Conditional Access posture: of 17 current CA policies, the 3 with "All users" scope are disabled (CA002) or enabledForReportingButNotEnforced (CA000, CA001). The 14 enabled policies are each scoped to a single group or a small user include (e.g. "MFA and Device Trust Required" — 2 users; the Microsoft-managed risky sign-in policy — 1 group), plus the isolation-tier policies.

Gaps

Gaps. PIM-eligible (just-in-time) role eligibility for the MFA-disabled set was not assessed; standing-vs-eligible role separation is not visible from the current-state assignment edges alone. Per-user effective CA coverage (the four-branch include/exclude evaluation) was not run member-by-member across all 302 accounts; the policy-level scan above shows no broadly-enforcing "All users" policy, but does not rule out narrow group-scoped coverage for individual members.

Ask follow up
Re-run triage
Close finding...
Details
SeverityCritical
StatusActive
Unclassified members4/4
DetectionDeparting-employee exfiltration
MITRE TacticExfiltration (TA0010)
Total runs6
MITRE TechniqueT1567
IDA-12345
Created onApril 28th, 2026 11:15:23 am
Recommendations
01
Revoke external Drive shares
Revoke the 247 external shares on files owned by Emily Grace. These shares persist after termination and grant ongoing access to customer data unless manually expired.
02
Transfer ownership of the Customer Master List
Reassign ownership of the Customer Master List shared drive to her manager. Emily currently holds sole ownership, and no DLP rule is configured to flag further bulk exports from this drive.
03
Remove Salesforce export permission
Remove the "Export Reports" permission from Emily Grace's Salesforce profile. She triggered a 4 GB report export yesterday and retains the ability to repeat it until termination.
03
Revoke GitHub write to billing-service
Downgrade Emily Grace's access on billing-service from write to read-only. She recently pulled 'customer_export.py' from this repo, and write access lets her push or rewrite history before departure.
Follow up inquiries
June 25
You
June 25
Randal Savage

Identity Threats are difficult to find. EDR and cloud security are built around endpoint and infrastructure. SIEMS are log streams. Identity threats are not on a single surface—They move across systems over time. Icite is purpose built to detect these threats.

How Icite works

Every identity, connected.

Across your systems and across time.

Every identity, connected.

Across your systems and across time.

Icite correlates event logs, config changes, and group relationships from every provider into one connected record per identity — and everything runs on it: detections, inquiries, posture.

IdentitiesSarah Chen
Isolate...
Respond
S
Sarah Chen
Identity
Entra ID4
sarah.chen@lumon.industries
Salesforce3
sarah.chen@lumon.industries
GitHub
sarah.chen@lumon.industries
Google
sarah.chen@lumon.industries
Workday
All Employees
Sales
Sales Engineering
App Access Without Group
Atlassian
1 day ago
Google Workspace
22 hours ago
O365
1 day ago
DocuSign
1 day ago
Ramp
3 days ago
Salesforce
22 hours ago
AWS
1 day ago
GitHub Enterprise
2 days ago
Postman
2 days ago
Claude
1 day ago
Sarah's Timeline
Last 30 days
July 7th
Application
Actor Email
Actor Name
Event
Target
Location and IP
July 8th
03:41:09.000 am MDT
Entra ID
sarah.chen@lumon.industries
sarah.chen@lumon.industries
Sign-in activity
Salesforce
198.51.100.36
04:47:08.000 am MDT
Google
sarah.chen@lumon.industries
sarah.chen@lumon.industries
drive change_user_access
Q3 pipeline review.csv
198.51.100.200
05:23:52.000 am MDT
Entra ID
sarah.chen@lumon.industries
sarah.chen@lumon.industries
Sign-in activity
Salesforce
198.51.100.56
07:08:21.000 am MDT
Entra ID
sarah.chen@lumon.industries
sarah.chen@lumon.industries
Sign-in activity
Google Workspace
198.51.100.155
07:16:20.000 am MDT
Atlassian Guard
sarah.chen@lumon.industries
sarah.chen@lumon.industries
comment_created
Unavailable
198.51.100.36
07:21:51.000 am MDT
Atlassian Guard
sarah.chen@lumon.industries
sarah.chen@lumon.industries
page_viewed
Unavailable
198.51.100.34
08:23:53.000 am MDT
Atlassian Guard
sarah.chen@lumon.industries
sarah.chen@lumon.industries
page_viewed
Unavailable
198.51.100.171
08:28:23.000 am MDT
Entra ID
sarah.chen@lumon.industries
sarah.chen@lumon.industries
Sign-in activity
GitHub
198.51.100.127
09:50:42.000 am MDT
Amazon Web Services
sarah.chen@lumon.industries
sarah.chen@lumon.industries
DescribeInstances
ec2.amazonaws.com
198.51.100.153
End of log events.
Fetch new events⇧R

Historical configuration changes

sarah.chen@lumen.industries

Feb 11

2026

Added to group sales-engineering

This grants access to Github Enterprise, AWS

Entra ID

By

Jared Keeso

Mar 24

2026

Profile changed to  sales-operations

This grants access to reports and dashboards

Salesforce

By

Helena Cole

Jun 13

2026

Added to group - q3-planning

Google Drive

By

Helena Cole

Jul 7

2026

Notice given - Termination date set for July 17

Workday

By

Helena Cole

Jul 8

2026

Personal access token created

None → Token created with no expiration

Github

By

Self

Jul 11

2026

Sharing changed on cust_master_list

Restricted → Anyone with link

Google Drive

By

Self

What we do

Identity singularity

We find and resolve identities across every application. A clear picture of who someone is, what they can access, how they got it, and what they've done with it.

AI-native detection engine

Describe the threat in plain English. Icite drafts the detection against events, config history, and the identity graph — then tunes it with you until it’s production ready.

Shrink identity risk

NHI, overprivileged accounts or stale access,Icite finds the risk that's been accumulating for years. We make it easy to eliminate attack surfaces before they’re exploited.

01 Detections

From idea to detection in minutes.

Stop waiting weeks for custom detections. Icite is built to enable your teams to write complex detections, specific to your environment, in minutes.

Custom detections

Drag and drop threat intel or simply just describe the threat you are looking to find.

Reduce alert fatigue

Maintaining and tuning detection is now a piece of cake with our agent-assisted tools.

50+ ready-to-go detections

We build and maintain detections that everyone can use. Easily copy and customize.

01 Detections

From idea to detection in minutes.

Stop waiting weeks for custom detections. Icite is built to enable your teams to write complex detections, specific to your environment, in minutes.

Custom detections

Drag and drop threat intel or simply just describe the threat you are looking to find.

Reduce alert fatigue

Maintaining and tuning detection is now a piece of cake with our agent-assisted tools.

50+ ready-to-go detections

We build and maintain detections that everyone can use. Easily copy and customize.

Tool comparison

Your SIEM, IGA, and XDR each see a slice.

Icite sees the identity.

CAPABILITY

Icite

SIEM

IGA

EDR/XDR

Resolve one person across every provider

Map access — what an identity can reach & how

Configuration history — replay any change over time

Correlate activity & events back to the identity

Custom identity detections in minutes

Pre-triaged findings with remediation suggestions

Active response — remove access / isolate

Non-human & agentic AI identities

Plain-language investigations across the stack

Tool comparison

Your SIEM, IGA, and XDR each see a slice.

Icite sees the identity.

Icite

Resolve one person across every provider

Map access — what an identity can reach & how

Configuration history — replay any change over time

Correlate activity & events back to the identity

Custom identity detections in minutes

Pre-triaged findings with remediation suggestions

Active response — remove access / isolate

Non-human & agentic AI identities

Plain-language investigations across the stack

SIEM

Resolve one person across every provider

Map access — what an identity can reach & how

Configuration history — replay any change over time

Correlate activity & events back to the identity

Custom identity detections in minutes

Pre-triaged findings with remediation suggestions

Active response — remove access / isolate

Non-human & agentic AI identities

Plain-language investigations across the stack

IGA

Resolve one person across every provider

Map access — what an identity can reach & how

Configuration history — replay any change over time

Correlate activity & events back to the identity

Custom identity detections in minutes

Pre-triaged findings with remediation suggestions

Active response — remove access / isolate

Non-human & agentic AI identities

Plain-language investigations across the stack

EDR/XDR

Resolve one person across every provider

Map access — what an identity can reach & how

Configuration history — replay any change over time

Correlate activity & events back to the identity

Custom identity detections in minutes

Pre-triaged findings with remediation suggestions

Active response — remove access / isolate

Non-human & agentic AI identities

Plain-language investigations across the stack

Value measured

Our goal is to help accelerate Security Operations.

Our goal is to help accelerate Security Operations.

90%

faster detection build and tune

25+

pre-built detections to customize

10x

faster investigations

Everything ITDR should do. And more.

Everything ITDR should do. And more.

Access graph

Understand an identity, what they have access to, how they get that access and what they've done with it.

Event timeline

A fast, easy way to search all of your event logs. No parsing, full payloads.

Fast response

Dynamically remove access to applications in seconds with Isolation.

Identity resolution

One person is a dozen different usernames across your tools. Icite stitches them into a single canonical identity automatically.

Custom reporting

Build the report your auditor, your board, or your CISO actually wants — not the canned dashboard a vendor decided to ship

Simple integrations

You only need to connect your IdP and HRIS to get started. Integrations take seconds to add.

Works with on-prem

Active Directory, on-prem LDAP, and self-hosted apps aren't legacy — they're where a large share of your privileged access still lives. Your identity coverage doesn't end at the firewall.

Export your data

Your findings, your enriched events, your detection definitions — all available by API or export. No vendor lock-in, no support ticket, no premium-tier paywall.

FAQ

Frequently Asked Questions

01

What is Icite?

Icite is an identity threat detection platform with the added capability of identity investigation.

02

What systems does Icite integrate with?

Icite connects via API to all major identity providers and most modern HRIS, cloud, and SaaS platforms. Icite can also easily connect to both on-prem Active Directory and LDAP.

03

Does Icite have a MCP?

Yes

04

How long until we see value?

Hours, not months. Connect three systems and Icite starts answering questions you couldn't answer before — no schema mapping, no ETL, no data lake required.

05

What kinds of questions can I ask Icite?

Anything that requires correlating identity, access, and activity across systems — the questions your team has historically given up on:

Anything that crosses systems — like "who can reach production but is no longer in our HRIS?" Plain English in, evidence-backed answers in seconds.

06

Does icite cover non-human and AI agent identities?

Yes — service accounts, tokens, and AI agents are first-class identities: discovered, mapped, and tied to a human owner.

07

Who is Icite built for?

Security teams that own identity investigations — SOC analysts, incident responders, identity engineers, and the CISOs and Heads of Identity who lead them. If your team is exporting data from four tools into a spreadsheet to answer access questions, Icite is built for you.

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc