Get Started with Behavior Threats
Focus
Focus
SaaS Security

Get Started with Behavior Threats

Table of Contents

Get Started with Behavior Threats

The Behavior Threats feature uses a machine-learning model and user history to detect potential threats based on anomalous user behavior.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Behavior Threats® is a user and entity behavior analytics (UEBA) capability within SaaS Security that helps you identify potential threats to your organization from compromised accounts, malicious insiders, and data breaches. Behavior Threats examines how your organization's users interact with sanctioned SaaS apps to identify suspicious activities that might indicate attempts to steal or corrupt data.
How Detection Works
Behavior Threats uses machine learning to establish behavioral baselines for each user, derived from up to 90 days of historical activity data. The platform continuously compares new user actions against these baselines to detect anomalous behavior. Two types of detection policies work together:
  • Dynamic Policies—ML-driven policies that compare user behavior against historical baselines to detect anomalies such as spikes in activity, suspicious geographic access, abnormal data transfers, and authentication anomalies.
  • Static Policies—Preconfigured threshold-based rules that detect specific threat indicators such as impossible travel, risky IPs, unsafe VPNs, and multi-channel DLP violations.
Transparent Risk Scoring
Behavior Threats assigns a risk score to each user based on a fully explainable model. Default weights are set for each policy to start with (higher the weight, higher the impact of the policy on the user's risk score). You can edit the weights (1 to 10) for both the ML baseline and each static policy and the platform compiles the score directly from those admin-configured weights. This transparency ensures you always understand exactly why a user was flagged and can tune the system to match your organization's risk appetite.
The Behavior Threats Workspace
The Behavior Threats page on Strata Cloud Manager surfaces key risk intelligence through dedicated tabs:
  • Dashboard—Displays top risky users, watchlist, user risk score breakdown, and the list of users generating incidents.
  • Users—Lists all users with their risk scores, severity levels, and incident counts. You can drill into individual user profiles to view activity timelines, CDUG membership, and take actions.
  • Watchlists—Lists all users who represent elevated risk to your organization. Assign a risk amplifier to each watchlist to increase the weight applied to a user's risk score, ensuring that high-priority personas receive proportionally higher scrutiny when policy violations occur.
  • Incidents—Shows all threat incidents with filtering by time range, severity, and policy type.
  • Policies—Displays configured detection policies and their most risky users.