BeyondTrust Identity Security Insights identity attack detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect identity-based attack activity that may indicate attempts to compromise user accounts, escalate privileges, or gain unauthorized access within the environment.

Strategy

Monitors identity activities that deviate from normal usage and are commonly associated with identity attacks.

Triage and Response

  1. Identify the affected account {{@entityName}} associated with the detected activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Assess whether the activity aligns with expected behavior, approved administrative actions, or normal user operations.
  4. If the activity is unauthorized, take appropriate containment, remediation, and recovery actions in accordance with established incident response.