Risk reduction · Security detection
Detect new and unknown attack behavior
Static rules and known signatures may not detect a new attack technique or an unusual sequence of individually permitted actions.
The record
Telemetry these decisions draw on
- User and workload behavior
- Privilege changes
- Administrative-tool usage
- Access patterns
- Identity lifecycle events
- Logging and control changes
- Network and cloud activity
The questions
What an agent answers
- Which sequences are rare or unprecedented?
- Does the behavior fit the identity's normal role?
- Are permitted actions being combined in a dangerous way?
- Is a dormant or unusual identity involved?
- What makes this sequence materially risky?
"No individual event violates policy, but the sequence is highly unusual: a dormant administrator account was reactivated, accessed a new environment, queried credentials, and disabled logging."
Related use cases
Browse the full library →Risk reduction
Detect fraud and transaction abuse
Refund abuse, promotion abuse, account takeover, and coordinated fraud can appear legitimate when each transaction is examined in isolation.
Investigations and forensics · Chief Financial Officer / Chief Information Security Officer
Read the use case →Risk reduction
Identify attack paths before attackers use them
Isolated vulnerabilities, identity weaknesses, network paths, and control gaps can combine into a realistic route to a critical system.
Security detection · Chief Information Security Officer
Read the use case →Risk reduction
Detect early signs of compromise
Early attack activity often appears as a set of weak signals that do not individually cross an alert threshold.
Security detection · Chief Information Security Officer
Read the use case →