Hello, you are using an old browser that's unsafe and no longer supported. Please consider updating your browser to a newer version, or downloading a modern browser.

Global Accelerated Learning • Est. 1999
Glossary Term Identity-Based Attack

Training Camp • Cybersecurity Glossary

What is Identity-Based Attack?

Identity-based attacks abuse stolen credentials, tokens, and identity systems to log in as legitimate users, evading detection and bypassing traditional defenses.

Glossary > Identity & Access Management > Identity-Based Attack

Understanding Identity-Based Attack

An identity-based attack is an intrusion that abuses legitimate credentials, tokens, or identity infrastructure rather than exploiting software vulnerabilities, allowing adversaries to log in instead of break in. Common techniques include credential theft, phishing, pass-the-hash, pass-the-ticket, MFA fatigue, and abuse of cloud identity providers. Because the activity uses valid accounts, it often blends with normal user behavior and evades signature-based detection, driving demand for identity threat detection and response (ITDR).

Learn More About Identity-Based Attack:

Ready to Get Certified?

Turn knowledge into credentials with our instructor-led cybersecurity boot camps.

View All Courses →