Analytical Algorithms
Unified Defense SIEM provides specialized analytical techniques designed to detect threats and rank events by risk level. By applying these techniques, Unified Defense SIEM reduces the number of events for security analysts to investigate. Risk ranking algorithms ensure that security analysts can focus their attention on key threats and actors behind the key threats. The following types of analytical algorithms are used in Unified Defense SIEM: Behavior-based algorithms monitor suspicious behavior compared to the entity’s past behavior or behavior of its peers. This section describes the supported behavior-based algorithms in Unified Defense SIEM. Rule-based algorithms trigger an alert when a specific condition is met. This section describes the supported rule-based algorithms in Unified Defense SIEM. Identity / Access policies use a built-in template to run against users and access accounts. These policies can include user-based policies that detect inherent risks such as poor perform
, function (e) { // Prevent Chrome 76 and later from showing the mini-infobar e.preventDefault(); // Stash the event so it can be triggered later. window[
Explore this link on the map →related reading
- Risk-Based Alerting: The New Frontier for SIEM | Splunksplunk.com
- Tuning YARA-L Rules in Chronicle SIEM | by Chris Martin (@thatsiemguy) | Mediummedium.com
- Use customizable anomalies to detect threats in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- How risk-based alerting works in Splunk Enterprise Security - Splunk Documentationdocs.splunk.com
- Reducing SIEM Alert Fatigue in 2026: How Tuning Improves Detection (Even with AI)redlegg.com
- Evolving Your SIEM Detection Rules: A Journey from Simple to Sophisticated | Databricks Blogdatabricks.com
- Model-Assisted Threat Hunting (M-ATH) with the PEAK Framework | Splunksplunk.com
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Exabeam Advanced SIEM and User Behavior Analytics Gives MTI a Clearer View of Risk Posture | Exabeamexabeam.com
- Securonix Documentationdocumentation.securonix.com