Skip to main content

Detecting Unauthorized Behavior From Legitimate Accounts

Incident Responders face an almost insurmountable amount of log events, and the move to the Cloud has only intensified this dependency on log data for intrusion analysis.Attackers are shifting techniques to utilize compromised accounts to hide their activity among the volume of legitimate business activity.Security teams struggle to detect and alert to this scenario as the ratio between time-to-discovery and time-to-compromise continues to exhibit a sizeable gap.A new approach is needed to tackle complex alerting using tools available to security teams.This paper defines a new methodology to detect unauthorized access from legitimate accounts.The paper also uses open-source tools to implement this methodology, providing a cost-effective solution available to all security teams.

sans-detecting-unauthorized-behavior-from-legitimate-accounts (PDF, 0.36MB)

22 Jun 2022
ByRodney Caudle
Share
All papers are copyrighted

No re-posting of papers is permitted

Subscribe to GIAC’s Monthly Newsletter

Receive expert insights, priority access to certifications, essential updates on regulatory changes and industry developments.