Also known as: UEBA, Behavioral Analytics
Security analytics that models normal activity for users, accounts, devices, and other entities so unusual behavior can be detected and investigated.
User and entity behavior analytics compares current activity with an established baseline for a user, identity, device, workload, or other entity. It helps surface changes that static rules may not recognize.
An anomaly is not automatically a threat. UEBA still needs reliable identity mapping, sufficient history, business context, and investigation evidence to separate unusual but legitimate work from dangerous activity.
UEBA is valuable for prioritization and discovery, but it should not turn every rare event into a high-severity incident.