logo

UEBA in the Real World: Catching Intrusions That Don’t Look Like Intrusions

ID: 2a255f3d-6d4c-534b-ba12-cd3d9a053e8f

STIX ID: report--2a255f3d-6d4c-534b-ba12-cd3d9a053e8f

Feed Name: Sekoia.io Blog (archive)

Date Published: 2026-03-13

Date Updated: 2026-04-29

Author: David Greenwood

...
...

This article argues that modern intrusions increasingly use legitimate credentials, APIs, and admin workflows to blend in, and demonstrates five practitioner cases (valid-account lateral movement, MFA fatigue, OAuth/app abuse, cloud-console misuse, and insider-style exfiltration) where UEBA and cross-telemetry correlation expose high-signal behavioral stories that simple IOC/rule-based detections miss; it recommends treating identity, OAuth/app governance, and cloud events as first-class telemetry and using behavioral baselines and contextual enrichment to surface high-quality alerts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.