14 / 16
SIEM
Review security events, configure detection rules and investigate alerts. Documented scenarios include repeated login failures, permission changes and after-hours connections, with alert severity, assignments and investigation history.
Give security teams a structured detection and investigation workflow.