UEBA
User and Entity Behavior Analytics
operationsmedium
UEBA tools build baselines of normal behavior for users, hosts, and service accounts, then flag deviations like a login from a strange country or a sudden mass download. Stolen credentials look legitimate, and behavior is often the only tell, so SOC teams use UEBA to catch insider threats and compromised accounts that rule-based detection misses.