A SIEM use case typically describes:
- a threat
- the necessary data
- a detection logic
- an alert
- a level of criticality
- an investigation procedure
- An answer.
Example :
Use case: Compromised privileged account
Sources:
- Active Directory
- Entra ID
- VPN
- EDR
- firewall.
Detection:
- unusual authentication
- followed by an increase in privileges
- followed by access to a critical server.
Action :
- critical alert
- investigation
- account verification
- Possibly blocking depending on the level of confidence.
This approach makes the SIEM truly operational.