Skip to main content

Advanced UEBA Dashboard

  • 19 August 2024
  • 0 replies
  • 202 views
Advanced UEBA Dashboard

 

Thanks @lgibson for providing this great idea!

 

Looking for visibility into Advanced UEBA with machine learning detections that automatically learn the baselines for different users and raise alerts when there are anomalous behaviors? Our latest Advanced UEBA Dashboard is here to help! 

 

This dashboard provides detailed visibility into the alerts generated by Advanced UEBA policies, which helps you perform user investigation & alert validation on this topic. With the dashboard, you can better understand why these alerts are being triggered and if your policies are working effectively.  

By default, the dashboard starts with a summary of Advanced UEBA alerts triggered in the last 30 days, including # alerts triggered, # apps with these alerts, and # users triggering these alerts. The # UCI Threshold Alerts triggered are highlighted, which is a starting point for your user investigation.

AD_4nXcAo9cBMMPwi2kpdLESYp_nQqpTXdu_OWx87sr4ofqC8HnwCdRy4EyHNsMSqFs_4mJNYSW0oGRx5aySJdHdlOOmwGvJBsmdA4Run6Me4bVyodaS5kGpKLOkfXdB8uFMppkYpz_WoW5RrQ8EG0W657rFWPM_?key=EePyTW9RApgXyZTq3QTsWg

Advanced UEBA automatically computes the User Confidence Index (UCI) score for every user on the platform. Users with the lowest UCI scores represent the highest risk to your organization. Manually monitoring all users is not scalable, and this is why we have implemented UCI Threshold Alerts. A UCI Threshold Alert is generated any time a user’s UCI score drops below a particular threshold, which is an indicator of security concerns in your environment. 

To learn more about who are the top users triggering these alerts, use the “top user” table below. Select any single user from the table to view all the data based on this user only. If you have implemented controls/coaching on risky user behaviors, use the trend line to understand if your effort is working as expected. 

AD_4nXcXA6alEvjzVIbqu4Pd0pKIzYwxb9lk6f1O0mOxcr7FXZ22dyAXIr8q0gUzz8FN8THg6oW_VayLWC1D-znPfPaWnhwt6QSj3bJi4iyas4WZqm6xtFIfA_3Zwn63rnH2ALBY9gx8rPDSB-Xr3G_CtbXgtmw?key=EePyTW9RApgXyZTq3QTsWg

Another trend line below provides visibility into how the Advanced UEBA policies are generating alerts over time. Use this widget to understand if your policies are working effectively. 

AD_4nXc_woQN_eBfqVc_AIsU6Jw9o5Gb07nkhBmaT--tXBTMWnOf4oZYO7ogzGU9DypG4vbV__v233HXaQy1yxqA-N0xbtFLW5fbeom4nm1tcwmolH5pqhwB8ebWruAkoJVncZvz-gcUcU2YGNhV1KxlE_ZPzzuF?key=EePyTW9RApgXyZTq3QTsWg

 

The second half of the dashboard provides visibility into Key Detection Scenarios, which is a starting point for your alert validation. The Key Detection Scenario shows the predominant reason for each user’s moderate or poor UCI score, which helps you recognize “why” the user’s UCI score is dropping. 

AD_4nXeomXBLQp-MSvQBF-j_aC9f2XtM_70UfIje2iwCaPlV-g3cqR4zh_aBvxtHdb9aYOdHGvgVM6FhOgSjLI0Sg4zQLZygzwP0R0X9xs0Wm2Ku2qVFaJqohjk4c5jPOZlMRC404Kxna_h36Bw2k1BVB5e1acgX?key=EePyTW9RApgXyZTq3QTsWg

With this part of the dashboard, you can better understand what Advanced UEBA policies are being triggered in your environment, which users are triggering these policies, and “why” they’re triggering these policies (Key Detection Scenarios). 

AD_4nXd1CMFBistOPhByiYiUEG6tnFZFAbIQWprffqTtioLg6u6WT6UEfU-X9sqXvYSoN7N8eIKbNb4RQeX0FeVo_V-8_E8jks1_-UnQkwbAJSnUu_-BWPqKvTXno5g8Eb-qe8fd3tD83cZ_Mh7fnOJHXPHwCBAr?key=EePyTW9RApgXyZTq3QTsWg

E.g. We see the Key Detection Scenario is “Insider threat - Data movement” above. This means the user is moving data from a corporate managed app to an unmanaged app/instance. The user may be exfiltrating sensitive data to a personal cloud storage app, which is an incident that should be further investigated.

 

Note: Key Detection Scenarios are manually mapped to Advanced UEBA policies through custom fields in this dashboard. If there are new Key Detection Scenarios and/or policies added, an updated version of this dashboard will be provided. 

 

The dashboard template is attached below. Feel free to import and view it in your own environment. Let us know if you have any questions & feedback!

Be the first to reply!

Reply