---
title: BeyondTrust Identity Security Insights identity attack detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  identity attack detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights identity attack detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect identity-based attack activity that may indicate attempts to compromise user accounts, escalate privileges, or gain unauthorized access within the environment.

## Strategy{% #strategy %}

Monitors identity activities that deviate from normal usage and are commonly associated with identity attacks.

## Triage and Response{% #triage-and-response %}

1. Identify the affected account `{{@entityName}}` associated with the detected activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Assess whether the activity aligns with expected behavior, approved administrative actions, or normal user operations.
1. If the activity is unauthorized, take appropriate containment, remediation, and recovery actions in accordance with established incident response.
