The escalation of privileges is a particularly important event.
A SIEM can search for:
- adding a user to a privileged group
- creation of an administrative account
- permission modification
- unusual use of a privileged account
- administrative authentication from a user workstation
- changes to security policies.
The goal is to identify behaviors that deviate from normal functioning.