Creating user baseline reports to identify malicious logins
ID: 593ad797-fa8d-57aa-9621-d5a8b84dae22
STIX ID: report--593ad797-fa8d-57aa-9621-d5a8b84dae22
Feed Name: Red Canary
The report outlines Red Canary’s method for creating dynamic, per-user identity baselines to improve detection and investigation of anomalous logins in cloud and SaaS environments. It describes a workflow that extracts and enriches 30 days of identity logs, applies Apriori analysis to identify common patterns and isolation forests for anomaly detection, and leverages LLM-generated summaries to provide concise, contextual insights that help analysts distinguish normal behavior from suspicious activity and reduce alert noise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
