The application learns about each user and creates a baseline of regular activities for each user and entity. Any activity that deviates from this baseline gets flagged as an anomaly. The UBA can identify user accounts taken over by attackers, because they exhibit anomalous behavior compared to the real business user.
Identify Priviledge Account Abuse
Rapidly identify anomalous entities without human analysis. Receive notification when there is an unusual volume of events.
User behavior can be associated to a risk categories not only on its volume. A set of dedicated widgets show, through trend indicators, the risk associated to users.
No advanced configuration needed because the SGBox UBA automatically checks for all different situations starting from events.