User and Entity Behaviour Analysis (UEBA) enables automated analysis of security data from SIEM, cloud systems, and security tools. UEBA solutions monitor the behaviour of users, applications, and other entities on the network, analysing their interactions with data and systems to identify anomalous behaviour.
UEBA can complement signature-based and rule-based detection with behavioural analytics by examining the behavioural patterns of humans and machines. UEBA can more easily detect internal threats, targeted attacks, financial fraud, and other threats that do not match known attack patterns or malware signatures.
UEBA accelerates the threat hunter’s ability to identify suspicious and anomalous behaviour and can also help threat hunters form hypotheses about the threat. Combined with threat Intelligence, UEBA can help threat hunters quickly initiate searches to see if anomalies on the network match up to known TTPs.