Behavior-Based Policy Example - Activity Outler
This behavior-based policy detects when a user uploads an abnormally high volume of data compared to their normal behavior. Behavior-based policies build a baseline for the volume of bytes out by transaction on web proxy for the account. The following example is the abnormal amount of data uploads to external storage sites policy. Go to Menu > Analytics > Policy Violations. Click > Create Policy. Under Define Policy, specify the following: For Functionality, choose Web Proxy. Under Define Risk and Threat, specify the following: Threat Indicator: Data egress via network uploads What actions should be taken when this policy is violated?: Some possible further analysis/triage steps to consider: Some possible remediation steps after further analysis/triage: Click Save & Next. Select Spike in Volume/Amount. Under Choose the Features for Generatomng Behavior, select bytesout [Bytes_Sent] and transactionstring1 [Transaction]. For Behavior Name, enter "Total bytes transmitted to external site
, function (e) { // Prevent Chrome 76 and later from showing the mini-infobar e.preventDefault(); // Stash the event so it can be triggered later. window[
Explore this link on the map →related reading
- Securonix Documentationdocumentation.securonix.com
- Securonix Documentationdocumentation.securonix.com
- Boxer: Data Analytics on Network-enabled Serverless Platformsresearch-collection.ethz.ch
- Anomalies detected by the Microsoft Sentinel machine learning engine | Microsoft Learnlearn.microsoft.com
- Advanced threat detection with User and Entity Behavior Analytics (UEBA) in Microsoft Sentinel | Microsoft Learnlearn.microsoft.com
- Create custom detection rules in Microsoft Defender XDR - Microsoft Defender XDR | Microsoft Learnlearn.microsoft.com
- Dealing with Noisy Behavioral Analytics in Detection Engineering | CMU Software Engineering Instituteinsights.sei.cmu.edu
- GitHub - suzana-ilic/study_model_behavior: Model Behavior Study Group · GitHubgithub.com
- MALT: A Dataset of Natural and Prompted Behaviors That Threaten Eval Integrity - METRmetr.org
- Baseline Hunting with the PEAK Framework | Splunksplunk.com
- Probe-Based Data Attribution: Surfacing and Mitigating Undesirable Behaviors in LLM Post-Traininggoodfire.ai
- GitHub - open-edge-platform/anomalib: An anomaly detection library comprising state-of-the-art algorithms and features such as experiment management, hyper-parameter optimization, and edge inference. · GitHubgithub.com