---
title: BeyondTrust Identity Security Insights sensitive data read activity detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  sensitive data read activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights sensitive data read activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect access to sensitive identity- or security-related data that may indicate unauthorized information gathering or misuse of elevated permissions.

## Strategy{% #strategy %}

Monitor identity platforms and security systems for read operations against sensitive objects, reports, or configurations. This detection focuses on identifying unusual access patterns or excessive data retrieval that could precede further compromise or targeted attacks.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the sensitive data access activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the access aligns with approved roles, responsibilities, and business requirements.
1. If the activity is suspicious, take appropriate remediation actions in accordance with established incident response.
