Petra Security
19 employees on LinkedIn · 2 known investors
Petra provides identity threat detection and response (ITDR) for Microsoft 365 environments, using behavioral models to detect account compromises and business email compromise, then automatically remediating attacker actions and producing forensic timelines. It is sold primarily to managed service providers (MSPs) to protect their clients, offering multi-tenant deployment, co-branded reporting, and insurance-grade forensics.
Investors · 2
Company profile
researched Aug 2026Petra Security is a security vendor focused on identity threat detection and response (ITDR) for Microsoft 365 environments, positioning its offering as "ITDR 2.0". Its product monitors identity and application activity in a tenant and surfaces account-takeover incidents through a per-user investigation view, presenting an "Attack Impact" summary that quantifies how long an attacker held access, how much of that delay was attributable to Microsoft audit-log publication lag, how quickly the detection fired after logs became available, and how quickly the session was contained.
The product's activity console organizes telemetry into views for logins, Exchange, SharePoint, Teams, authentication methods, devices, permissions, registered applications and URL clicks, and pairs it with user context such as user principal name, mailbox address, account creation date, job title, department, location and enrolled authentication methods. Individual events are enumerated with timestamps, the attacker action and target, and source IP metadata including ISP, hosting/proxy classification and geolocation. Event types shown include failed and successful sign-ins, pending MFA challenges, mailbox reads, updates and hard deletes of specific messages, sign-in and profile page access, and third-party mail client app registrations, over a selectable date range with refresh and export controls.
▸Full profile — market position, technology, go-to-market
Market position
Petra describes its category as ITDR 2.0, an evolution of identity threat detection and response applied to Microsoft 365 identities.
Technology
Petra's system ingests Microsoft 365 audit and sign-in telemetry and correlates it into a per-account timeline spanning logins, Exchange, SharePoint, Teams, authentication methods, devices, permissions, OAuth application registrations and URL clicks. Detection is timed against the publication of Microsoft audit logs, with the interface reporting log-delivery delay, time-to-detection after logs are published, and time-to-containment; containment removes the attacker's access from the account. Source IP addresses are enriched with ISP, infrastructure type (for example data center or proxy) and city/region/country geolocation, and mailbox-level actions are recorded at the level of individual message subjects to quantify what an intruder accessed, sent, modified or deleted.
Go-to-market
Organizations using Microsoft 365, with the product's example tenant depicting a corporate finance function (an accounts payable manager account) targeted by invoice- and payment-themed email fraud.
Compiled by commissioned research from 1 cited public sources — announcements, filings, and press listed under research sources below.
▸Research sources · 1
primary sources listed
- Petra Securitypetrasecurity.com · web
1 public sources were cited for this profile; the first-party ones are listed here.
Frequently asked questions
- What does Petra Security do?
- Petra Security offers identity threat detection and response for Microsoft 365 accounts, marketed as "ITDR 2.0".
- Who are Petra Security's investors?
- Petra Security's investors include Outsiders, Pathlight Ventures.

