Simple definition
IOA is a concept or mechanism used in cybersecurity to describe suspicious behaviour or action rather than a fixed artifact.
Technical definition
In a business environment, IAia intervenes primarily to describe suspicious behaviour or action rather than a fixed artifact. Its implementation depends on the architecture, equipment and security policies in place.
What’s the point?…
describe a suspicious behaviour or action rather than a fixed artifact.
Concrete example
a Power Shell sequence and task creation can trigger a detection.
Common problems
- missing context
- noise
- too wide a rule
To be noted: Always adapt the diagnosis to the version of the product and to the architecture actually deployed.