User and entity behaviour analytics. In Microsoft Sentinel, machine learning works out what typical activity looks like for each user, host, IP address and app, then surfaces deviations that could signal an attacker using a stolen account or a malicious insider.
Also called User and Entity Behavior Analytics.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains UEBA in context, with comparison tables and the common traps.
Terms in this definition
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Entity
Something like a product or customer that an organisation stores data about. Its characteristics are its attributes, and every individual record is one instance.
- Microsoft Sentinel
Microsoft's cloud-native SIEM, with SOAR capabilities, which stores and queries its data in a Log Analytics workspace.
- ML
Building models that infer patterns from data so they can predict outcomes, for instance through regression or classification, using tools like Azure Machine Learning or Synapse Spark pools. Predictive ML is distinct from generative AI.
- LIKE
Compares strings with a pattern that can contain the % and _ wildcards. Because it only understands character patterns, searching big volumes of text this way is much slower than using full-text search.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Related terms
- BehaviorAnalytics
Holds enriched UEBA events in Microsoft Sentinel and feeds entity pages. Each row carries an InvestigationPriority between 0 and 10 indicating how far from normal the event is.