Attack Detection
Attack Detection is ADT’s real-time recognition system for identifying malicious actions as they unfold.
Modern attacks rarely announce themselves. They emerge as fragments of behaviour scattered across logs, cloud events, identities, and network activity. Detecting them requires more than signatures. It requires an intelligence system that understands how adversaries operate and how your environment behaves normally.
Attack Detection in ADT is built for this purpose. It identifies malicious activity at the behavioural level, recognizing tactics and techniques before they escalate into incidents.
What Attack Detection Does
ADT’s detection system monitors incoming signals in real time. It interprets patterns across cloud, infrastructure, applications, and identity systems to determine if an attack is underway.
Behavioural Recognition
ADT recognizes attack tactics such as reconnaissance, credential abuse, lateral movement, payload deployment, policy tampering, and data extraction.
Intent Classification
The system reads more than the surface. It evaluates whether an action is accidental, exploratory, or malicious.
Technique Mapping
ADT maps behaviours to recognized attack patterns.
This includes reconnaissance paths, brute force attempts, exploit chains, privilege escalation attempts, and suspicious execution flows.
Early Warning
ADT detects attacks in their earliest stages.
Small signals can trigger timely caution when tied to broader patterns.
Why It Matters
Detection defines the line between a minor alert and a major breach.
By understanding attacker behaviour, ADT reduces the time it takes to identify a threat and improves accuracy across the entire security posture.
Teams gain:
- fewer false positives
- clearer understanding of activity intent
- stronger visibility into emerging risk
- faster paths to mitigation
- a reliable layer of early protection
How It Works
Attack Detection uses multi-stage reasoning:
- Signals arrive from agentless streams, agents, cloud logs, or the API.
- ADT evaluates the behaviour against learned baselines.
- Suspicious sequences are identified and correlated.
- A detection verdict is generated with a threat score.
- Explanations, evidence, and recommended actions are produced.
Detected attacks flow directly into Active Defense or incident queues.
Key Strengths
Precise Behavioural Understanding
Recognizes attacks by how they behave, not just what they match.
High Context Awareness
Considers time, user identity, origin, environment state, and historical activity.
Adaptable to Every Environment
ADT learns patterns unique to each organization without custom rules.
Clear, Explainable Results
Detection outputs include narrative reasoning, context, and evidence.





