Log360 uses correlation rules that analyze the sequence of events leading to a software installation. When an installation is preceded by suspicious patterns like multiple failed VPN login attempts, successful authentication from an unusual location, and rapid progression through the network, the system flags it for investigation. The solution examines the context and timing of events rather than just the installation itself.