BeyondTrust Identity Security Insights suspicious account behavior detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect unusual or suspicious account behavior that may indicate account misuse, policy violations, or potential compromise.

Strategy

Monitor identity logs to identify account behaviors that deviate from normal usage patterns or established security standards.

Triage and Response

  1. Identify the account {{@entityName}} associated with the suspicious behavior.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the observed behavior aligns with approved business use, organizational policies, and expected account ownership.
  4. If the activity is unauthorized, take appropriate remediation actions in accordance with incident response procedures.