All seven modules

Module 03 · Nerv-ID · Human identity

Identity Threat Detection & Response

Business email compromise, account takeover and identity attacks, detected and stopped in real time.

Identity is the perimeter now. Nerv-ID monitors Microsoft 365 and Google Workspace, and when it detects a threat it acts: revoke sessions, force a password reset, delete the malicious inbox rule, block the OAuth app.

2
Identity platforms in one product
12
Identity threat detections
Auto
Containment without human approval

What it detects

  • Impossible travel between logins
  • Business email compromise and CEO fraud
  • Password spray across many accounts
  • Malicious inbox and forwarding rules
  • Brute force on a single account
  • OAuth consent attacks
  • MFA fatigue push bombing
  • Privilege escalation and CA policy change
  • Legacy protocol abuse bypassing MFA
  • Token theft and session reuse
  • Mass download and external sharing
  • Per-user behavioural deviation

The attack chain Nerv-ID correlates

  1. 01Password spray from a single hosting IP across 40 mailboxes
  2. 02One successful authentication, no MFA prompt, legacy protocol
  3. 03Inbox rule created on the CFO mailbox to auto-delete replies
  4. 04Payment redirection email sent to a supplier from a real account

Where it separates

01Both platforms, one product.
Microsoft 365 and Google Workspace monitored together, which matters the moment you acquire a firm on the other stack.
02AI-powered BEC detection.
Email patterns analysed for payment redirection, authority pressure and urgency manipulation, not just rule changes.
03Attack chains, not alerts.
Password spray, successful login, inbox rule, payment email arrives as one linked kill chain instead of four tickets.
04Response without a human.
Sessions revoked and rules deleted automatically, because a two hour response window is the whole loss event.
Capability comparison8 capabilities
CapabilityTypical ITDR and bundled identityNerv-ID
Microsoft 365 monitoringYesYes
Google Workspace monitoringRarelyYes
BEC and payment fraud detectionBasic or noneAI-powered
Automated containmentLimitedFull
Attack chain correlationNoYes
Per-user behavioural baselinePartialYes
Elevated executive monitoringNoYes
Needs an extra licenceUsually a premium tierNo

Capability summary of the identity threat detection market as at August 2026, prepared from publicly available product documentation. Capability varies materially by licence tier and configuration. Verify current inclusions with any vendor you are comparing.