It may compare observations with explicit policy, a historical baseline, peer groups, expected process patterns, or known adversary behavior. Inputs can span identities, endpoints, applications, networks, cloud services, workloads, and operational systems.
Methods range from deterministic rules and statistics to graph analysis and machine learning. Outputs commonly include anomalies, risk scores, clusters, or correlated leads that analysts or automated controls evaluate with context. The approach can support detection, hunting, fraud analysis, insider-risk work, and control monitoring.
Key points
Questions firstDefine the behavior of interest, the entities and time window, required observations, expected comparison, and the decision the result is intended to support.
ContextAccount for asset purpose, identity lifecycle, maintenance, seasonality, peer selection, architecture, business processes, and known changes before treating variation as suspicious.
GovernanceMinimize and protect collected data, control access and retention, assess workforce and privacy effects, explain consequential results, and provide review and correction paths.
Important limitationUnusual behavior is not necessarily malicious, and malicious behavior may resemble routine activity. Missing telemetry, drifting or poisoned baselines, biased peer groups, opaque scoring, and changing systems can produce false confidence as well as false alerts.