Identity Anomaly Detection
Detecting unusual identity behavior that may signal compromise, such as logins at odd times or locations, impossible travel, or atypical access, by comparing current activity against an established baseline of normal.
Concept Neighborhood
Start here
Identity Telemetry
The foundation Identity Anomaly Detection builds on, worth understanding first.
Identity TelemetryStart here
The activity data generated by identity systems, sign-ins, authentication results, privilege changes, access grants, and federation events, that feeds detection, hunting, and investigation of identity-based threats.
6
lessons
Baseline Analysis
Establishing what normal activity looks like in an environment so that deviations stand out as worth investigating. In detection and SIEM work, the baseline is the reference against which anomalies are measured.
5
lessons
IAM Threat Detection
6
lessons
Identity Hunting Value
6
lessons
Identity Risk Scoring
6
lessons
Impossible Travel Hunting
6
lessons
IAM Detection for Meridian
5
lessons
Conditional Access
2
lessons
Show 1 more connection
Related Lessons
1 lesson covers this conceptSign in to open lesson content directly.
