Start with Identity
← Glossary
Concept

UEBA

User and Entity Behavior Analytics. Machine-learning analysis of normal behavior to flag anomalies that signal compromise or insider risk. A common building block of identity threat detection.

UEBA is the analytic layer under most identity detection, and its value depends entirely on the baseline: a model trained during a period that already contained the intrusion learns the intrusion as normal. It works best on high-signal identity events (impossible travel, first-time privileged action, unusual consent grant) and worst as a general anomaly firehose that buries the analyst.

See also: what is ITDR, account takeover, lateral movement, ITDR vendors

Last reviewed By SWI Community TeamSuggest a correctionHow we research