BeyondTrust Identity Security Insights suspicious authentication activity detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect suspicious authentication activity that may indicate unauthorized access attempts, compromised credentials, or abnormal sign-in behavior.

Strategy

Monitor authentication events across identity platforms to identify sign-ins that deviate from established user behavior patterns or organizational security expectations.

Triage and Response

  1. Identify the account {{@entityName}} associated with the suspicious authentication activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the activity aligns with expected user behavior, approved access patterns, and organizational security policies.
  4. If the activity is unauthorized, take appropriate response actions in accordance with incident response.