The escalation of privileges is a particularly important event.

A SIEM can search for:

  • adding a user to a privileged group
  • creation of an administrative account
  • permission modification
  • unusual use of a privileged account
  • administrative authentication from a user workstation
  • changes to security policies.

The goal is to identify behaviors that deviate from normal functioning.

Categories: