SIEM is not solely intended for external attackers.

It can also help to detect unusual internal behaviors.

For example :

  • massive file consultation
  • access to resources unrelated to functions
  • unusual use of a privileged account
  • massive download
  • permission modification
  • access outside normal hours.

However, be aware:

An anomaly is not necessarily fraud. The SIEM identifies events or behaviors to investigate; it should not be used to automatically conclude that human error occurred.

Categories: