BeyondTrust Identity Security Insights endpoint risk detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect endpoint risks that may expose user accounts, credentials, or authentication sessions to compromise.

Strategy

Monitor activity and endpoint signals to identify risk indicators associated with compromised, unmanaged, or non-compliant devices.

Triage and Response

  1. Identify the affected account or device associated with the detected activity {{@entityName}}.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the endpoint and activity align with organizational security standards and acceptable use policies.
  4. If the endpoint is non-compliant, take appropriate actions in accordance with incident response and endpoint security.