BeyondTrust Identity Security Insights suspicious multi-factor authentication activity detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect suspicious or potentially risky multi-factor authentication (MFA) activity.

Strategy

Monitor MFA-related events across identity platforms to identify abnormal changes, unusual authentication patterns, or deviations from expected MFA usage.

Triage and Response

  1. Identify the affected account {{@entityName}} associated with the suspicious MFA activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the activity aligns with approved user behavior, support processes, and organizational security policies.
  4. If the activity is suspicious, take appropriate remediation actions in accordance with incident response.