BeyondTrust Identity Security Insights suspicious session activity detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect suspicious or anomalous user session activity that may indicate session misuse, hijacking, or unauthorized access to organizational resources.

Strategy

Monitor session activity across identity and access platforms to identify abnormal behaviors such as unexpected session reuse, anomalous access patterns, or deviations from typical user session characteristics.

Triage and Response

  1. Identify the affected account {{@entityName}} associated with the suspicious session activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Validate whether the session activity can be explained by legitimate user behavior or approved operational processes.
  4. If the activity is suspicious, take appropriate containment and remediation actions in line with incident response policies.