---
title: BeyondTrust Identity Security Insights suspicious session activity detected
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > BeyondTrust Identity Security Insights
  suspicious session activity detected
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# BeyondTrust Identity Security Insights suspicious session activity detected

{% alert level="danger" %}
This rule is part of a beta feature. To learn more, [contact Support](https://docs.datadoghq.com/help/).
{% /alert %}
Classification:attack 
## Goal{% #goal %}

Detect suspicious or anomalous user session activity that may indicate session misuse, hijacking, or unauthorized access to organizational resources.

## Strategy{% #strategy %}

Monitor session activity across identity and access platforms to identify abnormal behaviors such as unexpected session reuse, anomalous access patterns, or deviations from typical user session characteristics.

## Triage and Response{% #triage-and-response %}

1. Identify the affected account `{{@entityName}}` associated with the suspicious session activity.
1. Review the information associated with the alert to understand the nature and potential impact of the activity.
1. Validate whether the session activity can be explained by legitimate user behavior or approved operational processes.
1. If the activity is suspicious, take appropriate containment and remediation actions in line with incident response policies.
