Anomalous Logins

Anomalous logins may signify suspicious activity. This often includes logins of a user into computers they don't normally log into, logins outside of a routine pattern on certain days of the week, also by time of day, or logins into a particular workstation or server outside of a certain set of users.

Sections on this page

SIEM Events

Office 365 New Country Activity
AIS Managed SIEM

Last modified March 25, 2021