Microsoft Threat Intelligence @threatintel.microsoft.com · Apr 28

With the expansion of Microsoft Sentinel User and Entity Behavior Analytics (UEBA) into new data sources spanning multi-cloud, identity providers, and authentication logs, defenders can detect behavioral anomalies across hybrid environments from a single place. msft.it/63327vHE7v

2 likes 1 replies

?

Replies

Microsoft Threat Intelligence · Apr 28

Microsoft Sentinel UEBA enriches raw AWS logs with simple binary behavioral insights (true/false) derived from baseline user, peer, and device behavior patterns such as first-time geography, uncommon ISP, unusual action, and abnormal operation volume.