logo

The unusual suspects: Effectively identifying threats via unusual behaviors

ID: c3e0a8aa-088a-5b0e-ba65-fb282a3fecdd

STIX ID: report--c3e0a8aa-088a-5b0e-ba65-fb282a3fecdd

Feed Name: Red Canary

Date Published: 2025-01-28

Date Updated: 2026-04-29

Author: Sam Straka

...
...

The report outlines Red Canary’s method for reducing noise and improving threat detection in identity, cloud, and SaaS environments by combining user baselines, real-time anomaly detection, and agentic investigation workflows. By establishing per-user and organizational baselines, flagging unusual behaviors at scale, and enriching them with 40+ contextual questions (e.g., ISP rarity, VPN/TOR use, MFA changes), the approach aims to distinguish benign anomalies from true risks and deliver higher-fidelity, analyst-ready findings.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.