BeyondTrust Identity Security Insights suspicious identity activity detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect suspicious identity-related activity that may indicate misuse, misconfiguration, or potential compromise of identities within the environment.

Strategy

Monitor identity events to identify behaviors that deviate from expected operational processes. This detection focuses on surfacing identity activities that may introduce security gaps.

Triage and Response

  1. Identify the account {{@entityName}} associated with the suspicious activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the activity aligns with approved identity management processes, user intent, and organizational policies.
  4. If the activity is unauthorized, take appropriate remediation actions in accordance with incident response.