UEBA
User and Entity Behavior Analytics. Machine-learning analysis of normal behavior to flag anomalies that signal compromise or insider risk. A common building block of identity threat detection.
UEBA is the analytic layer under most identity detection, and its value depends entirely on the baseline: a model trained during a period that already contained the intrusion learns the intrusion as normal. It works best on high-signal identity events (impossible travel, first-time privileged action, unusual consent grant) and worst as a general anomaly firehose that buries the analyst.
See also: what is ITDR, account takeover, lateral movement, ITDR vendors
Related on Start with Identity
- GlossaryITDR
Identity Threat Detection and Response. Security tooling that detects and responds to identity-based attacks such as account takeover, privilege escalation, and
- GlossaryISPM
Identity Security Posture Management. Continuous assessment of identity-related misconfigurations and risk, such as dormant accounts, weak MFA coverage, and ris
- GlossaryCredential Stuffing
An attack that replays username and password pairs leaked from other breaches against a target, exploiting password reuse. Defended with MFA, passkeys, and bot
- BlogOkta buys Permiso Security to put ITDR inside the identity provider
Okta signed a definitive agreement to acquire Permiso Security, reportedly for just under 200 million dollars in an almost all-cash deal. It moves detection of
- BlogSilverfort acquires Fabrix Security, a one-year-old AI access-decision engine
Price undisclosed, reported as tens of millions for a company founded in 2025. Fabrix supplies the identity knowledge graph and decisioning; Silverfort supplies