Overview
IronWiFi ITDR (Identity Threat Detection and Response) turns the authentication telemetry your wireless network already produces into continuous threat detection. Nine detection engines analyze every RADIUS authentication and accounting event, captive portal session, AI agent authentication, and OpenRoaming federation transaction in real time - detecting 50+ threat types mapped to 30+ MITRE ATT&CK techniques, with per-identity risk scoring from 0 to 100 and mean time to detect under 30 seconds.
Keep Your Existing RADIUS
ITDR is a drop-in product on any standards-compliant RADIUS infrastructure - FreeRADIUS, NPS, ISE, or IronWiFi Cloud RADIUS. There are no agents to deploy and no migration required: you keep your existing RADIUS servers, IronWiFi ingests authentication events, and detection runs centrally. Deployment is a configuration change, not an infrastructure project.
Nine Detection Engines
- Credential attacks - brute force, password spray, credential stuffing, replay, EAP downgrade
- Identity anomalies - per-identity behavioral baselines: hours, APs, devices, EAP methods, locations
- Certificate threats and device spoofing - certificate misuse, MAC/identity mismatch
- Mid-session hijack and data exfiltration - RADIUS accounting analysis (Start/Interim/Stop)
- Captive portal fraud - voucher stuffing and portal-layer abuse
- Insider threats - deviation scoring for privileged and long-tenured identities
- AI agent compromise and Shadow AI discovery - detection for machine identities on the network
- OpenRoaming federation abuse - roaming authentication analysis
Respond Automatically
Detections trigger automated response through RADIUS Change of Authorization (CoA), session blocking, or certificate revocation. Choose your posture per engine: Shadow (observe), Detect (alert), or Enforce (act). Every detection exports to Splunk, Microsoft Sentinel, Elastic, QRadar, or Datadog via syslog/CEF and webhooks.
Security and Compliance
IronWiFi holds a SOC 2 Type II report issued by Johanson Group LLP. The platform processes 50M+ authentications per month for 1,000+ organizations in 108 countries. Patents pending.
Getting Started
- Subscribe to a tier sized to your monitored identities (a unique user/NAI in the trailing 30 days - a user with 5 devices counts once)
- Point your RADIUS accounting/auth event stream at IronWiFi (guided setup for FreeRADIUS, NPS, and major controllers)
- Run in Shadow mode while baselines build, then enable Detect and Enforce per engine
Already an IronWiFi Cloud RADIUS customer? ITDR runs in the same tenant with zero additional collectors - contact sales@ironwifi.com for a bundle private offer. Product documentation: https://www.ironwifi.com/itdr
Highlights
- First WiFi-native ITDR platform: 9 detection engines analyze every RADIUS, captive portal, AI agent, and OpenRoaming authentication - 50+ threat types, 30+ MITRE ATT&CK techniques, per-identity risk scoring, mean time to detect under 30 seconds.
- Agent-free and RADIUS-agnostic - drops in on FreeRADIUS, NPS, ISE, or IronWiFi Cloud RADIUS with no migration and no endpoint software. Automated response via RADIUS CoA, session blocking, and certificate revocation; exports to Splunk, Sentinel, Elastic, QRadar, and Datadog.
- SOC 2 Type II report issued by Johanson Group LLP. Platform processes 50M+ authentications monthly across 1,000+ organizations in 108 countries. Patents pending.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
Dimension | Description | Cost/month |
|---|---|---|
ITDR Essential - 1,000 identities | WiFi identity threat detection for up to 1,000 monitored identities - 4 of 9 detection engines, Shadow + Detect modes, MITRE ATT&CK mapped. | $499.00 |
ITDR Plus - 5,000 identities | WiFi identity threat detection for up to 5,000 monitored identities - all 9 engines incl. Insider Threat, automated response via RADIUS CoA (Shadow + Detect + Enforce). | $1,499.00 |
ITDR Enterprise - 25,000 identities | WiFi identity threat detection for up to 25,000 monitored identities - all 9 engines + Shadow AI Discovery, multi-tenant SOC integration, 24/7 support. | $4,999.00 |
Vendor refund policy
To request a refund, contact support@ironwifi.com within 30 days of your initial purchase. Refunds for unused subscription time are reviewed on a case-by-case basis, and approved refunds are processed through AWS Marketplace.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Software as a Service (SaaS)
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Support
Vendor support
Getting Help
Email support@ironwifi.com for technical assistance with configuration, event ingestion, detection tuning, or account questions. Standard support is included with every subscription plan.
Response Times
- Business-tier subscriptions: 4-hour response target, Monday through Friday (business hours), with priority handling for production-impacting issues.
- Standard-tier subscriptions: best-effort response during business days.
Self-Service Resources
Product documentation, RADIUS integration guides (FreeRADIUS, NPS, and major wireless controllers), and onboarding walkthroughs are available at https://www.ironwifi.com/itdr . If you need hands-on guidance during initial setup, email support with your RADIUS platform and event volume for step-by-step instructions tailored to your environment.
Billing, Refunds, and Subscription Changes
For billing inquiries, subscription changes, or refund requests, contact support@ironwifi.com with your AWS Marketplace subscription details. Private offer customers with custom terms should reference their agreement for specific support provisions.
Escalation
If an issue is not resolved within the stated response window, reply to your existing support thread to escalate.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.