View Threats and Incidents
Focus
Focus
SaaS Security

View Threats and Incidents

Table of Contents


View Threats and Incidents

Use the Behavior Threats dashboard to view detects threats and incidents.
Where Can I Use This?What Do I Need?
  • Strata Cloud Manager
  • Data Security license
Or any of the following licenses that include the Data Security license:
  • CASB-X
  • CASB-PA
Depending on when you first activated and configured Data Security, up to 90 days of historical user data is available to Behavior Threats. Behavior Threats examines this historical user data, and, using data-driven machine learning models combined with admin-configurable static policy weights, assigns a risk score to each user.
Only SaaS apps that support user activity generate data to Behavior Threats. For example, Microsoft Office 365 supports user activity, while Slack Enterprise does not support user activity.
  • Dashboard—The landing page displays key metrics and widgets including Top Risky Users (with risk trend, incident count, watchlist membership, and status), Top Policies (enabled policies with the most recent incidents), and Top Incidents (the most critical recent incidents). You can interact with each widget and click View More to access detailed information.
  • Users—Displays threat details for each user on your tenant, including risk score, incident count, and watchlist membership. From this tab, you can access individual user profiles to view their activity timeline, CDUG membership, and take actions such as resetting their risk score or downloading a report.
  • Incidents—Displays all threat incidents detected by Behavior Threats. You can filter by time range (up to 90 days), severity, and policy type to focus your investigation.
  • Policies—Shows all configured policies with their most risky users. You can view policies in a grid or list view to monitor which policies are generating the most incidents.