← All Netgraph solutions
UEBADetect & Respond

Behaviour analytics that show their work.

Netgraph UEBA runs a 20-model catalog — 19 live, one honestly marked planned — spanning the full Gartner analytics taxonomy, from KNN outliers and K-Means peer grouping to Bayesian risk networks and streaming online learning. Every entity gets a 0–100 risk score with a human-readable rationale, risk decay and a full score ledger — explainable analytics, not a black-box number.

20-model catalog19 live62 use-cases incl. BFSIExplainable 0–100 riskFull Gartner taxonomyDPDP-aligned privacy

What is UEBA (User & Entity Behaviour Analytics)?

UEBA builds a baseline of how each user, host, and service account normally behaves — when they log in, what they access, how much data they move — and scores deviations that rules can't anticipate: the credentialed insider, the compromised account acting 'almost' normally, the service account that suddenly reads a customer table. Netgraph runs 20 behaviour models across 62 use-cases and publishes an explainable 0-100 risk score for every entity — explainable meaning an analyst can see exactly which behaviours moved the score, not just a number.

What ships in the module

A full analytics stack — and every score explains itself.

01

20-model catalog

KNN outlier, K-Means peer grouping, PCA feature analysis, Markov sequence, HDBSCAN, STL time-series, streaming/online learning (River), DGA detection, AutoML, Bayesian risk network, sentiment analysis, Soundex/fuzzy link analysis, isolation forest, ECOD, LOF, a triage scorer and three detector primitives (first-occurrence, rarity, sequence). 19 live; a deep-learning intent model is honestly marked planned.

02

Explainable risk (XAI)

Per-entity 0–100 score with a human-readable rationale — which factors fired, at what weight — plus risk decay over time and a score ledger auditing every change.

03

62-use-case content library

A curated library of behavioural use-cases including BFSI sector packs — deploy what fits your environment instead of authoring from zero.

04

Peer groups that explain WHY

Peer grouping comes with a shared-host relationship graph that shows the evidence behind every grouping — you can see why two entities are peers, not just that the model says so.

05

Baselines & deviations

A dedicated console for per-entity baselines and their deviations — the raw material every detector primitive and model builds on.

06

Visual Rule Canvas

Compose behavioural rules on a visual canvas whose vocabulary is aligned to the live detectors — what you can drag is what actually runs.

07

Watchlists with activity logs

Watch users, entities and endpoint hosts, with per-list activity logs — focused monitoring for leavers, privileged accounts or flagged machines.

08

Entity Context lookup

One lookup fusing five sources — including UEM endpoint posture from the unified agent — into a single entity picture for triage and investigation.

09

Model registry & ops

Configurable hyperparameters and per-model enable/shadow mode, ML jobs & AIOps for training and operations, a simulation harness for validating scenarios end-to-end, and DPDP-aligned pseudonymization controls for privacy.

Explainability, first-class

A risk score you can defend in a review meeting.

When UEBA raises an entity to 87, the console shows exactly which models contributed, which behaviours deviated from which baseline, and how the score decayed and re-accumulated over time. The score ledger keeps the audit trail; the shared-host peer graph shows the comparison population; the rationale reads like an analyst wrote it.

  • Factor-by-factor breakdown with weights — no unexplained composite.
  • Risk decay and a score ledger — scores age honestly and every change is recorded.
  • Shadow mode lets a new model score silently before it influences risk.
  • The simulation harness fires labelled scenarios end-to-end — prove a detector works before you rely on it.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Behavior AnalyticsThe analytics overview across users and entitiesUEBA ▸ Behavior Analytics
UEBA RiskExplainable 0–100 entity risk with rationale, decay and score ledgerUEBA ▸ UEBA Risk
Baselines & DeviationsPer-entity baselines and their deviationsUEBA ▸ Baselines & Deviations
Peer GroupsK-Means peer grouping with a shared-host relationship graph explaining membershipUEBA ▸ Peer Groups
Entity ContextFused lookup across 5 sources including UEM endpoint postureUEBA ▸ Entity Context
Content Library62 behavioural use-cases including BFSI sector packsUEBA ▸ Content Library
Rule CanvasVisual rule composition, vocabulary aligned to the live detectorsUEBA ▸ Rule Canvas
UEBA ModelsModel registry: hyperparameters, enable/shadow per model; ML jobs & AIOpsUEBA ▸ UEBA Models
WatchlistsUsers, entities and endpoint hosts under watch, with activity logsUEBA ▸ Watchlists

Common questions

UEBA — asked and answered

Why do most UEBA deployments go stale, and how does Netgraph avoid it?+

Standalone UEBA tools drift because their baselines live apart from the response loop — nobody re-tunes what nobody uses. Netgraph's UEBA writes risk scores onto the same graph entities the SOC agents investigate every day, so model output is continuously exercised, validated by analysts, and fed back. Our blog post 'UEBA after the honeymoon' covers this in depth.

Is the risk scoring explainable?+

Yes — every 0-100 entity score decomposes into the specific behavioural deviations that produced it, with links to the underlying events on the graph. That matters for analyst trust and for defending actions taken on the basis of the score.

What use-cases does Netgraph UEBA cover?+

62 shipped use-cases across insider threat, account compromise, privilege abuse, data staging and exfiltration, service-account anomalies, and impossible-travel/access-pattern detection — running on 20 behaviour models.

See it live

Ask why an entity scored 87. Get an answer that reads like an analyst.