A SIEM can highlight different types of anomalies.

For example :

  • connection from an unusual country;
  • connection at an unusual time;
  • increasing number of authentication failures;
  • unexpected creation of an account;
  • elevation of privileges;
  • unusual execution of PowerShell;
  • modification of a security policy;
  • disabling an antivirus program;
  • connection to a critical server;
  • massive file transfer;
  • unusual network traffic;
  • firewall rule modification;
  • log deletion;
  • unusual access to a database.

The goal is not simply to detect a known signature.

A properly configured SIEM can also look for behavioral patterns.

Categories: