BeyondTrust Identity Security Insights privileged access change detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect changes to privileged access assignments that may increase risk by granting elevated permissions.

Strategy

Monitor identity activity for modifications to privileged roles, policies, or permissions. This detection focuses on identifying unexpected or high-impact privilege changes that could enable unauthorized access, persistence, or misuse of administrative capabilities.

Triage and Response

  1. Identify the account {{@entityName}} associated with the privileged access change.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the change aligns with approved access requests and organizational governance processes.
  4. If the activity is suspicious, take appropriate remediation actions in accordance with established incident response procedures.