An attack does not usually stop at the first compromised position.

The attacker may attempt to move to other systems.

The SIEM can search for unusual sequences such as:

User workstation → server → other server → domain controller

or:

User account → elevated privileges → access to multiple systems

The correlation of events becomes particularly useful in this type of scenario.

Categories: