SECAI Core · phase 13 of 15
User and entity behavior analytics
A system that can provide automated identification of suspicious activity by user accounts and computer hosts.
The Explain card
- Plain English
- UEBA automatically profiles how user accounts and machines normally behave, then flags activity that breaks the pattern, without needing a predefined signature.
- Example
- A service account that normally calls the internal LLM API a few times an hour suddenly begins downloading fine-tuning datasets at three in the morning. UEBA scores the deviation and alerts the SOC.
- Why it matters
- Insider threats and stolen credentials look like legitimate users. Behaviour, not identity, gives them away, and AI systems with privileged data access are exactly what those users target.
- Hook
- It is not who you are, it is what you usually do.
Where it sits in the deck
Phase 13: Detection, Monitoring, and Threat Intelligence
Defences eventually fail — learn how to detect, correlate, and investigate anomalies in real time across both AI-specific and traditional security telemetry.