4 By Energy SOAR Best practice SOAR 01 Sep: How to detect and handle technical account misuse incidents? You can create a correlation rule in your SIEM to detect a login attempt from different than usual client IP which could mean a breach or a misuse.