Risk reduction · Security detection

Detect new and unknown attack behavior

Static rules and known signatures may not detect a new attack technique or an unusual sequence of individually permitted actions.

The record

Telemetry these decisions draw on

  • User and workload behavior
  • Privilege changes
  • Administrative-tool usage
  • Access patterns
  • Identity lifecycle events
  • Logging and control changes
  • Network and cloud activity

The questions

What an agent answers

  • Which sequences are rare or unprecedented?
  • Does the behavior fit the identity's normal role?
  • Are permitted actions being combined in a dangerous way?
  • Is a dormant or unusual identity involved?
  • What makes this sequence materially risky?
Example agent output
"No individual event violates policy, but the sequence is highly unusual: a dormant administrator account was reactivated, accessed a new environment, queried credentials, and disabled logging."

We use cookies to provide essential site functionality and, with your consent, to analyze site usage and enhance your experience. View our Privacy Policy