Behaviour analytics that show their work.
Netgraph UEBA runs a 20-model catalog — 19 live, one honestly marked planned — spanning the full Gartner analytics taxonomy, from KNN outliers and K-Means peer grouping to Bayesian risk networks and streaming online learning. Every entity gets a 0–100 risk score with a human-readable rationale, risk decay and a full score ledger — explainable analytics, not a black-box number.
What is UEBA (User & Entity Behaviour Analytics)?
UEBA builds a baseline of how each user, host, and service account normally behaves — when they log in, what they access, how much data they move — and scores deviations that rules can't anticipate: the credentialed insider, the compromised account acting 'almost' normally, the service account that suddenly reads a customer table. Netgraph runs 20 behaviour models across 62 use-cases and publishes an explainable 0-100 risk score for every entity — explainable meaning an analyst can see exactly which behaviours moved the score, not just a number.
What ships in the module
A full analytics stack — and every score explains itself.
Explainability, first-class
A risk score you can defend in a review meeting.
When UEBA raises an entity to 87, the console shows exactly which models contributed, which behaviours deviated from which baseline, and how the score decayed and re-accumulated over time. The score ledger keeps the audit trail; the shared-host peer graph shows the comparison population; the rationale reads like an analyst wrote it.
- Factor-by-factor breakdown with weights — no unexplained composite.
- Risk decay and a score ledger — scores age honestly and every change is recorded.
- Shadow mode lets a new model score silently before it influences risk.
- The simulation harness fires labelled scenarios end-to-end — prove a detector works before you rely on it.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Behavior Analytics | The analytics overview across users and entities | UEBA ▸ Behavior Analytics |
| UEBA Risk | Explainable 0–100 entity risk with rationale, decay and score ledger | UEBA ▸ UEBA Risk |
| Baselines & Deviations | Per-entity baselines and their deviations | UEBA ▸ Baselines & Deviations |
| Peer Groups | K-Means peer grouping with a shared-host relationship graph explaining membership | UEBA ▸ Peer Groups |
| Entity Context | Fused lookup across 5 sources including UEM endpoint posture | UEBA ▸ Entity Context |
| Content Library | 62 behavioural use-cases including BFSI sector packs | UEBA ▸ Content Library |
| Rule Canvas | Visual rule composition, vocabulary aligned to the live detectors | UEBA ▸ Rule Canvas |
| UEBA Models | Model registry: hyperparameters, enable/shadow per model; ML jobs & AIOps | UEBA ▸ UEBA Models |
| Watchlists | Users, entities and endpoint hosts under watch, with activity logs | UEBA ▸ Watchlists |
Common questions
UEBA — asked and answered
Why do most UEBA deployments go stale, and how does Netgraph avoid it?+
Standalone UEBA tools drift because their baselines live apart from the response loop — nobody re-tunes what nobody uses. Netgraph's UEBA writes risk scores onto the same graph entities the SOC agents investigate every day, so model output is continuously exercised, validated by analysts, and fed back. Our blog post 'UEBA after the honeymoon' covers this in depth.
Is the risk scoring explainable?+
Yes — every 0-100 entity score decomposes into the specific behavioural deviations that produced it, with links to the underlying events on the graph. That matters for analyst trust and for defending actions taken on the basis of the score.
What use-cases does Netgraph UEBA cover?+
62 shipped use-cases across insider threat, account compromise, privilege abuse, data staging and exfiltration, service-account anomalies, and impossible-travel/access-pattern detection — running on 20 behaviour models.
See it live
Ask why an entity scored 87. Get an answer that reads like an analyst.
Works with everything on the graph
EDR / EPP
UEM inventory from the unified agent feeds the endpoint-posture risk factor and the Entity Context lookup.
Explore→NextGen SIEM
UEBA models score the same normalised telemetry the SIEM ingests — one data plane, no duplicate pipeline.
Explore→Agentic AI SOC
Explainable risk gives the AI SOC agents a rationale to reason over — not just a number to threshold.
Explore→