Each organization must adapt its rules to its environment, but certain categories often provide a relevant starting point:
- numerous connection failures
- Connection successful after numerous failures
- unusual privileged authentication
- creating an administrator account
- modification of a privileged group
- deactivation of a security mechanism
- unusual execution of PowerShell
- accessing a critical server from a user workstation
- Unusual VPN activity
- connection from an unusual location
- massive data transfer
- communication with an indicator of compromise
- log deletion or interruption
- unusual activity on backups.