A SIEM can highlight different types of anomalies.
For example :
- connection from an unusual country;
- connection at an unusual time;
- increasing number of authentication failures;
- unexpected creation of an account;
- elevation of privileges;
- unusual execution of PowerShell;
- modification of a security policy;
- disabling an antivirus program;
- connection to a critical server;
- massive file transfer;
- unusual network traffic;
- firewall rule modification;
- log deletion;
- unusual access to a database.
The goal is not simply to detect a known signature.
A properly configured SIEM can also look for behavioral patterns.