Security Operations

UEBA

Detect anomalies without surveilling your workforce

Behavior analytics is the sharpest tool against compromised accounts and insider threats, and the most sensitive at the same time: it evaluates what people do. UEBA in isidaten is therefore built around governance. The module stays locked until a legal basis is documented. Works-agreement profiles define tenant-wide which detectors run, what evaluations refer to and how long the learning phase lasts. Personal references are pseudonymized, and every re-identification is audited. On this foundation the analytics operate: baselines per identity and entity, anomaly detectors, risk scoring with escalation and forensics for confirmed suspicion.

DSGVO
Features

Your benefits

1

Governance before analytics

Activation lock until a documented legal basis and works-agreement profiles with detector switches: co-determination is built in, not retrofitted.

2

Work pseudonymously, re-identify with an audit trail

Analysts see pseudonyms instead of names. Only substantiated suspicion justifies re-identification, and each one is logged.

3

Baselines, detectors, risk score

Identity and entity behavior is learned from SIEM events; deviations raise the risk score, up to escalation as an incident.

Capabilities

All capabilities at a glance

  • Activation lock until a documented legal basis
  • Works-agreement profiles: detector switches, evaluation scope, learning phase
  • Pseudonymization with audited re-identification
  • Baselines per identity & entity (SIEM-based)
  • Anomaly detectors & risk scoring with escalation
  • Forensics view for confirmed suspicion
  • Mass encryption detector: write, rename and delete waves on file shares
  • Three rules: known ransom extensions, rename wave with extension change, baseline outlier
  • Deliberately alerts during the learning phase too, because the damage happens in minutes
  • A “files affected” panel on the anomaly, user profiles masked until authorised re-identification
  • File activity watch as an agent task on the file server, aggregated per interval
  • MITRE mapping T1486, plus T1485 when the share of deletions is high
Result

Behavior analytics your works council and DPO can support, because their conditions live in the module, not in an appendix.

Experience UEBA live

Schedule a no-obligation demo – we will show you the module with your own use cases.