Active Directory remains a particularly important target in many Windows environments.
An attacker who progressively compromises the directory might search for:
- privileged accounts
- groups
- machines
- relationships of trust
- accessible resources.
Active Directory logs can therefore become extremely valuable.
A SIEM can monitor, among other things:
- authentications
- chess
- group changes
- account creation
- privilege modifications
- administrative events
- unusual access.
Identity protection must therefore be considered a major component of SIEM use cases.