The unusual suspects: Effectively identifying threats via unusual behaviors
ID: c3e0a8aa-088a-5b0e-ba65-fb282a3fecdd
STIX ID: report--c3e0a8aa-088a-5b0e-ba65-fb282a3fecdd
Feed Name: Red Canary
The report outlines Red Canary’s method for reducing noise and improving threat detection in identity, cloud, and SaaS environments by combining user baselines, real-time anomaly detection, and agentic investigation workflows. By establishing per-user and organizational baselines, flagging unusual behaviors at scale, and enriching them with 40+ contextual questions (e.g., ISP rarity, VPN/TOR use, MFA changes), the approach aims to distinguish benign anomalies from true risks and deliver higher-fidelity, analyst-ready findings.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
