User and Entity Behavior Analytics (UEBA)
A security approach that uses analytics to detect abnormal behavior by users or devices that could indicate a compromise or insider threat.
User and entity behavior analytics (UEBA) is a security approach that establishes a baseline of normal behavior for each user and device on a network, then uses machine learning and statistical analysis to flag deviations that could indicate a compromised account, insider threat↗, or malware↗.
Unlike traditional rule-based detection, UEBA can catch subtle anomalies, such as a user logging in at an unusual hour or accessing files they've never touched before, that wouldn't trigger a fixed alert. This makes it particularly effective against slow-moving or novel attacks that don't match known signatures.