All seven modules
Module 03 · Nerv-ID · Human identity
Identity Threat Detection & Response
Business email compromise, account takeover and identity attacks, detected and stopped in real time.
Identity is the perimeter now. Nerv-ID monitors Microsoft 365 and Google Workspace, and when it detects a threat it acts: revoke sessions, force a password reset, delete the malicious inbox rule, block the OAuth app.
- 2
- Identity platforms in one product
- 12
- Identity threat detections
- Auto
- Containment without human approval
What it detects
- Impossible travel between logins
- Business email compromise and CEO fraud
- Password spray across many accounts
- Malicious inbox and forwarding rules
- Brute force on a single account
- OAuth consent attacks
- MFA fatigue push bombing
- Privilege escalation and CA policy change
- Legacy protocol abuse bypassing MFA
- Token theft and session reuse
- Mass download and external sharing
- Per-user behavioural deviation
The attack chain Nerv-ID correlates
- 01Password spray from a single hosting IP across 40 mailboxes
- 02One successful authentication, no MFA prompt, legacy protocol
- 03Inbox rule created on the CFO mailbox to auto-delete replies
- 04Payment redirection email sent to a supplier from a real account
Where it separates
- 01Both platforms, one product.
- Microsoft 365 and Google Workspace monitored together, which matters the moment you acquire a firm on the other stack.
- 02AI-powered BEC detection.
- Email patterns analysed for payment redirection, authority pressure and urgency manipulation, not just rule changes.
- 03Attack chains, not alerts.
- Password spray, successful login, inbox rule, payment email arrives as one linked kill chain instead of four tickets.
- 04Response without a human.
- Sessions revoked and rules deleted automatically, because a two hour response window is the whole loss event.
Capability comparison8 capabilities
| Capability | Typical ITDR and bundled identity | Nerv-ID |
|---|---|---|
| Microsoft 365 monitoring | Yes | Yes |
| Google Workspace monitoring | Rarely | Yes |
| BEC and payment fraud detection | Basic or none | AI-powered |
| Automated containment | Limited | Full |
| Attack chain correlation | No | Yes |
| Per-user behavioural baseline | Partial | Yes |
| Elevated executive monitoring | No | Yes |
| Needs an extra licence | Usually a premium tier | No |
Capability summary of the identity threat detection market as at August 2026, prepared from publicly available product documentation. Capability varies materially by licence tier and configuration. Verify current inclusions with any vendor you are comparing.