# What is User and Entity Behavior Analytics (UEBA)?

> User and entity behavior analytics is an analytical approach that models activity associated with users and other entities, then identifies deviations or combinations of behavior that may deserve investigation.

- Canonical URL: https://yellowcube.eu/glossary/user-and-entity-behavior-analytics/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

Entities can include accounts, devices, applications, services, and workloads. UEBA may use rules, statistics, peer-group comparisons, and machine-learning methods to combine identity, endpoint, network, cloud, and application evidence.

The output is usually a risk score, anomaly, or investigative lead rather than a verdict. A new location, unusual transfer volume, or rare administrative action may indicate compromise, misuse, or a legitimate change in duties. Conversely, a capable attacker may imitate ordinary behavior. Analysts need supporting context and evidence before taking high-impact action.

### Key points

- **Useful context:** Identity lifecycle, asset criticality, peer groups, authentication, device state, data access, known changes, and prior investigative outcomes.
- **Operational controls:** Monitor data quality and model drift, explain why a score changed, test performance across populations, and provide a review path for affected people.
- **Governance needs:** Define a proportionate purpose, minimize and protect behavioral data, set retention and access rules, and assess legal, privacy, and workforce implications.
- **Important limitation:** An anomaly is not proof of malicious intent or account compromise. Baselines can encode incomplete, biased, or already-compromised behavior, and risk scores can create false confidence when their assumptions are hidden.

### Related terms

[Behavioral analytics](<https://yellowcube.eu/glossary/behavioral-analytics/>) · [Insider threat](<https://yellowcube.eu/glossary/insider-threat/>) · [Insider risk management](<https://yellowcube.eu/glossary/insider-risk-management/>)

### Sources

[NIST glossary: UEBA](https://csrc.nist.gov/glossary/term/user_and_entity_behavior_analytics) · [NIST SP 800-215](https://csrc.nist.gov/pubs/sp/800/215/final) · [CISA Insider Threat Mitigation Guide](https://www.cisa.gov/sites/default/files/2022-11/Insider%20Threat%20Mitigation%20Guide_Final_508.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

