Investigate

Console route · /ueba

UEBA

Behavioral ranking of users, devices, and service accounts with timelines, linked incidents, and approval-gated identity response requests. Scores come from control-plane records — not from a claim of proprietary model training shipped in-console.

Job of this page

UEBA helps operators prioritize which identities and devices look anomalous relative to peer context, then drill into timelines and linked cases. It is an investigation aid over control-plane entity behavior records, not a standalone UEBA product with a hidden model library in the current codebase.

How to use it

The entity table filters by kind and risk/flag. Charts summarize risk distribution, anomalies, and activity. Detail tabs cover overview, timeline, and linked incidents or assets. From an entity, operators may request session revoke or MFA reset subject to response permissions and approval.

Live mode calls fetchUebaEntities (and related APIs). If the API is unavailable, the page says so and can offer evaluation data explicitly — it does not silently substitute.

Boundaries

Do not read this page as proof of a proprietary trained ML baseline library shipping in the console today. Scores and flags come from control-plane records or evaluation fixtures. Identity response still requires human approval scopes.

Privacy controls

Your visit should be as controlled as your telemetry.

We use necessary cookies to keep the site working. Optional analytics help us understand which product pages are useful. Marketing cookies stay off unless you allow them.