SECAI Core · phase 13 of 15

User and entity behavior analytics

A system that can provide automated identification of suspicious activity by user accounts and computer hosts.

The Explain card

Plain English
UEBA automatically profiles how user accounts and machines normally behave, then flags activity that breaks the pattern, without needing a predefined signature.
Example
A service account that normally calls the internal LLM API a few times an hour suddenly begins downloading fine-tuning datasets at three in the morning. UEBA scores the deviation and alerts the SOC.
Why it matters
Insider threats and stolen credentials look like legitimate users. Behaviour, not identity, gives them away, and AI systems with privileged data access are exactly what those users target.
Hook
It is not who you are, it is what you usually do.

Where it sits in the deck

Phase 13: Detection, Monitoring, and Threat Intelligence

Defences eventually fail — learn how to detect, correlate, and investigate anomalies in real time across both AI-specific and traditional security telemetry.