UEBA in the Real World: Catching Intrusions That Don’t Look Like Intrusions
ID: 2a255f3d-6d4c-534b-ba12-cd3d9a053e8f
STIX ID: report--2a255f3d-6d4c-534b-ba12-cd3d9a053e8f
Feed Name: Sekoia.io Blog (archive)
This article argues that modern intrusions increasingly use legitimate credentials, APIs, and admin workflows to blend in, and demonstrates five practitioner cases (valid-account lateral movement, MFA fatigue, OAuth/app abuse, cloud-console misuse, and insider-style exfiltration) where UEBA and cross-telemetry correlation expose high-signal behavioral stories that simple IOC/rule-based detections miss; it recommends treating identity, OAuth/app governance, and cloud events as first-class telemetry and using behavioral baselines and contextual enrichment to surface high-quality alerts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
