Security Operations
Cut off access when an account is compromised
Cantina detects signs of takeover in Okta, Entra ID, and Google Workspace, investigates the activity, and cuts off compromised access.
Respond to attackers using legitimate accounts
An attacker with a stolen session can use a legitimate account to access company systems. Cantina's Identity & Access agent investigates the activity and follows the response procedure for that attack.
Match the response to the detected account threat
- 01
Detect suspicious activity
Watch supported identity providers for signs of account takeover.
- 02
Investigate the account
Run the triage procedure for the detected attack.
- 03
Contain access
Cut off the compromised access identified in the investigation.
r.malik@acme.com
new device · Lagos → Austin, 4m apart
-
Suspicious sign-in detected
okta · impossible travel
-
Triage procedure run
account takeover · 14 checks
-
Sessions revoked
6 active sessions killed
-
Access contained
tokens rotated · MFA reset
Investigate identity threats across the providers you use
-
Okta, Entra ID, Google Workspace, and more
Monitor account activity across these identity providers.
-
Attack-specific procedures
Choose the investigation path based on the detected threat.
-
14 response procedures
Use the Identity & Access agent's defined procedures for investigation and response.
-
Access containment
Stop continued use of the compromised access.
What security teams say about Cantina
Cantina is the first platform we have used that carries the work through from finding an issue to driving the fix, and it lets my team operate like one far larger than it is. We keep finding new uses for it across our security program.
Matt Mock
Chief Information Security Officer
See how Cantina investigates and contains an account takeover
See the activity Cantina checks and how it contains access in your identity provider.