Active Directory remains a particularly important target in many Windows environments.

An attacker who progressively compromises the directory might search for:

  • privileged accounts
  • groups
  • machines
  • relationships of trust
  • accessible resources.

Active Directory logs can therefore become extremely valuable.

A SIEM can monitor, among other things:

  • authentications
  • chess
  • group changes
  • account creation
  • privilege modifications
  • administrative events
  • unusual access.

Identity protection must therefore be considered a major component of SIEM use cases.

Categories: