Discussion about this post

User's avatar
Jeff Martin's avatar

My complaint about UEBA has always been that 'behavioral' anomalies are overall quite common and almost all false positives. There is nothing inherently malicious about an anomaly. Every time I have looked at an anomaly that was actually malicious, there is always some much simpler method of detection because something happened that should never happen. Looking at failed logons followed by success? That's a false positive factory. It happens all the time, with a lot of different causes.

Expand full comment

No posts