Delinea Privilege Manager unusual spike in application justification events
Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel,
n'hésitez pas à nous contacter.
Goal
Detects an unusual spike in application justification events.
Strategy
This rule monitors the Delinea Privilege Manager logs to detect an unusual spike in application justification events.
Triage and Response
- Analyze the application justification events to identify the users, applications, and computers that are contributing significantly to the spike.
- Identify whether the spike involves applications flagged as suspicious or bad.
- Determine if these justifications (user reasons) were for legitimate business needs or potential misuse.
- If suspicious or unauthorized justifications are identified, revoke or restrict the privileges granted to the affected applications.
- Review change history logs to identify any recent modifications to policies or permissions causing spike and if a misconfiguration is found, revert to a more secure policy.