User and Entity Behavior Analytics
Also known as:UEBA
User and Entity Behavior Analytics: Detects anomalous behavior by users, devices, and services using analytics. This capability supports the early detectionDetectionThe capability to identify suspicious activity, attacks, or policy violations in time. of suspicious activity. Achieving good results requires high-quality data sourcesData SourceA system, sensor, log, or repository that supplies data for security analysis and decisions., aligned detection logic, triage, and continuous optimizationContinuous OptimizationOngoing tuning of rules, processes, and resources using measured operational results..
How it works and where it fits
User and Entity Behavior Analytics connects data sources to detection or assessment logic. Raw records become security-relevant only when timing, identity, system context, and expected behavior are considered. Rules, correlations, statistical models, and analyst decisions may work together; no single method reliably covers every attack pattern.
Practical security relevance
Operational quality is reflected in coverage, data completeness, detection time, and false-alert workload. Data sources need owners, time synchronization, retention, and quality controls. Detections should be tested, versioned, and improved using real incidents. Every meaningful alert also requires triage guidance, escalation, and possible response actions.
Related concepts
- Behavioral AnalyticsBehavioral AnalyticsAnalyzes user and system behavior to detect suspicious deviations.: Analyzes user and system behavior to detect suspicious deviations.
- Anomaly DetectionAnomaly DetectionDetects unusual patterns that may indicate attacks or misconfigurations.: Detects unusual patterns that may indicate attacks or misconfigurations.
- Identity Threat Detection and ResponseIdentity Threat Detection and ResponseDetection and handling of attacks targeting identities, accounts, and authentication systems.: Detection and handling of attacks targeting identities, accounts, and authentication systems.
- Detection EngineeringDetection EngineeringSystematic development, testing, and maintenance of rules for attack detection.: Systematic development, testing, and maintenance of rules for attack detection.