SecOps
UEBA / Peer Analytics
User and Entity Behavior Analytics establishes a rolling 30-day baseline of normal access patterns per user and service account. Anomaly scoring flags: access volume significantly above peer group average, secrets accessed outside historical working hours, first-time access to a resource or workspace, bulk secret enumeration in a short window, and repeated failed access attempts.
Flagged events appear in the Security Events queue with an anomaly score and contributing factors. High-score events can trigger automatic approval requirement escalation.
Key Configuration
- Baseline window (days)
- Peer grouping (workspace / role / department)
- Anomaly score threshold for alerting
- Automatic escalation threshold
- Suppression rules for known automation accounts