---
title: BeyondTrust Identity Security Insights suspicious account behavior detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  suspicious account behavior detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights suspicious account behavior detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect unusual or suspicious account behavior that may indicate account misuse, policy violations, or potential compromise.

## Strategy{% #strategy %}

Monitor identity logs to identify account behaviors that deviate from normal usage patterns or established security standards.

## Triage and Response{% #triage-and-response %}

1. Identify the account `{{@entityName}}` associated with the suspicious behavior.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the observed behavior aligns with approved business use, organizational policies, and expected account ownership.
1. If the activity is unauthorized, take appropriate remediation actions in accordance with incident response procedures.
