Performing User Behavior Analytics
Overview
Cybersecurity skill for performing user behavior analytics. Follows industry best practices and security standards.
When to Use
Trigger phrases:
- "performing user behavior analytics"
- "SOC teams need to detect compromised accounts through abnormal authentication pa"
- "Insider threat programs require behavioral monitoring beyond rule-based detectio"
- "Impossible travel or geographic anomalies indicate credential compromise"
Use this skill when:
- SOC teams need to detect compromised accounts through abnormal authentication patterns
- Insider threat programs require behavioral monitoring beyond rule-based detection
- Impossible travel or geographic anomalies indicate credential compromise
- Privileged account monitoring requires baseline deviation detection
Do not use as the sole basis for disciplinary action — UEBA findings are indicators requiring investigation, not proof of malicious intent.
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- SIEM with 30+ days of authentication and access log history for baseline creation
- VPN, O365, and Active Directory authentication logs normalized to CIM
- GeoIP database (MaxMind GeoLite2) for location-based anomaly detection
- Identity enrichment data (department, role, manager, typical work hours)
- Splunk Enterprise Security with UBA module or equivalent UEBA capability
Workflow
# Example: IOC detection
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: str) -> dict:
return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}
- Plan Operations — Define objectives, scope, and success criteria for user behavior analytics operations.
- Prepare Environment — Set up tools, access, and data sources required for user behavior analytics.
- Execute Core Workflow — Perform the user behavior analytics operations following established procedures.
- Validate Results — Verify that results meet quality standards and objectives.
- Report Findings — Document results, observations, and recommendations.
- Follow Up — Track remediation actions and verify fixes where applicable.
Tools
- Analysis Platform — Data processing and visualization
- Collaboration Tools — Team coordination and knowledge sharing
Process
- Design — Define interface, identify patterns, plan implementation
- Implement — Write code following existing conventions, add tests
- Verify — Run tests, check integration, validate behavior
Verification
Anti-Rationalization Table
| Rationalization |
Reality |
| "We are too small to be targeted" |
Automated attacks target everyone. Size does not matter. |
| "Security slows us down" |
A breach slows you down 100x more. Build security in from the start. |
| "We will fix it after launch" |
Vulnerabilities in production are exploited within hours. Fix before deploy. |
1---2name: performing-user-behavior-analytics3description: Use when performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.4license: Apache-2.05---67# Performing User Behavior Analytics89## Overview1011Cybersecurity skill for performing user behavior analytics. Follows industry best practices and security standards.1213## When to Use1415**Trigger phrases:**16- "performing user behavior analytics"17- "SOC teams need to detect compromised accounts through abnormal authentication pa"18- "Insider threat programs require behavioral monitoring beyond rule-based detectio"19- "Impossible travel or geographic anomalies indicate credential compromise"202122Use this skill when:23- SOC teams need to detect compromised accounts through abnormal authentication patterns24- Insider threat programs require behavioral monitoring beyond rule-based detection25- Impossible travel or geographic anomalies indicate credential compromise26- Privileged account monitoring requires baseline deviation detection2728**Do not use** as the sole basis for disciplinary action — UEBA findings are indicators requiring investigation, not proof of malicious intent.293031## When NOT to Use3233- When you lack proper authorization for testing34- For production systems without change management35- When the task requires legal or compliance expertise beyond technical scope363738## Prerequisites3940- SIEM with 30+ days of authentication and access log history for baseline creation41- VPN, O365, and Active Directory authentication logs normalized to CIM42- GeoIP database (MaxMind GeoLite2) for location-based anomaly detection43- Identity enrichment data (department, role, manager, typical work hours)44- Splunk Enterprise Security with UBA module or equivalent UEBA capability4546## Workflow4748```python49# Example: IOC detection50import re5152IOC_PATTERNS = {53 "ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",54 "domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",55 "hash_md5": r"\b[a-f0-9]{32}\b",56 "hash_sha256": r"\b[a-f0-9]{64}\b",57}5859def extract_iocs(text: str) -> dict:60 return {k: re.findall(v, text) for k, v in IOC_PATTERNS.items()}61```62631. **Plan Operations** — Define objectives, scope, and success criteria for user behavior analytics operations.642. **Prepare Environment** — Set up tools, access, and data sources required for user behavior analytics.653. **Execute Core Workflow** — Perform the user behavior analytics operations following established procedures.664. **Validate Results** — Verify that results meet quality standards and objectives.675. **Report Findings** — Document results, observations, and recommendations.686. **Follow Up** — Track remediation actions and verify fixes where applicable.6970## Tools7172- **Analysis Platform** — Data processing and visualization73- **Collaboration Tools** — Team coordination and knowledge sharing747576## Process77781. **Design** — Define interface, identify patterns, plan implementation791. **Implement** — Write code following existing conventions, add tests801. **Verify** — Run tests, check integration, validate behavior8182## Verification8384- [ ] All user behavior analytics procedures executed completely and documented85- [ ] Findings validated against multiple data sources86- [ ] False positives identified and filtered87- [ ] Results documented with evidence and timestamps88- [ ] Recommendations provided with risk-based prioritization8990## Anti-Rationalization Table9192| Rationalization | Reality |93|---|---|94| "We are too small to be targeted" | Automated attacks target everyone. Size does not matter. |95| "Security slows us down" | A breach slows you down 100x more. Build security in from the start. |96| "We will fix it after launch" | Vulnerabilities in production are exploited within hours. Fix before deploy. |