# What is Behavioral Analytics?

> Behavioral analytics is a broad analytical approach that examines activity, sequences, relationships, and changes over time to identify behavior that is relevant to a security question.

- Canonical URL: https://yellowcube.eu/glossary/behavioral-analytics/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

It may compare observations with explicit policy, a historical baseline, peer groups, expected process patterns, or known adversary behavior. Inputs can span identities, endpoints, applications, networks, cloud services, workloads, and operational systems.

Methods range from deterministic rules and statistics to graph analysis and machine learning. Outputs commonly include anomalies, risk scores, clusters, or correlated leads that analysts or automated controls evaluate with context. The approach can support detection, hunting, fraud analysis, insider-risk work, and control monitoring.

### Key points

- **Questions first:** Define the behavior of interest, the entities and time window, required observations, expected comparison, and the decision the result is intended to support.
- **Context:** Account for asset purpose, identity lifecycle, maintenance, seasonality, peer selection, architecture, business processes, and known changes before treating variation as suspicious.
- **Governance:** Minimize and protect collected data, control access and retention, assess workforce and privacy effects, explain consequential results, and provide review and correction paths.
- **Important limitation:** Unusual behavior is not necessarily malicious, and malicious behavior may resemble routine activity. Missing telemetry, drifting or poisoned baselines, biased peer groups, opaque scoring, and changing systems can produce false confidence as well as false alerts.

### Related terms

[User and entity behavior analytics (UEBA)](<https://yellowcube.eu/glossary/user-and-entity-behavior-analytics/>) · [Detection engineering](<https://yellowcube.eu/glossary/detection-engineering/>) · [Threat hunting](<https://yellowcube.eu/glossary/threat-hunting/>) · [Security telemetry](<https://yellowcube.eu/glossary/security-telemetry/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>)

### Sources

[NIST IR 8219: Securing Manufacturing Industrial Control Systems—Behavioral Anomaly Detection](https://csrc.nist.gov/pubs/ir/8219/final) · [MITRE ATT&CK Detection Strategies](https://attack.mitre.org/detectionstrategies/)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

