BeyondTrust Identity Security Insights abnormal administrator activity detected

This rule is part of a beta feature. To learn more, contact Support.
beyondtrust-identity-security-insights

Classification:

attack

Goal

Detect potentially abnormal or high-risk administrative activity.

Strategy

Monitor administrative activity across identity systems and managed assets to identify actions that deviate from expected usage patterns.

Triage and Response

  1. Identify the administrator account {{@entityName}} associated with the detected activity.
  2. Review the information associated with the alert to understand the nature and potential impact of the activity.
  3. Evaluate whether the activity aligns with approved administrative responsibilities and organizational security policies.
  4. If the activity is unauthorized, take appropriate action in accordance with established incident response.