Exabeam has been a pioneer in AI since 2013. Exabeam was built on the foundation of machine learning (ML) for UEBA and automation of the threat detection, investigation, and response (TDIR) workflow.
ML applications include:
- Event Correlation Analytics: Stateful user tracking correlates and analyzes raw stateless events to coherent units, providing a full history of user activities for alert triage.
- Statistical Analysis: Over 750 models track behaviors of network entities, confirming model convergence and performing outlier analysis.
- Context Estimation: Dynamically determines a user’s peer grouping for anomaly analysis and identifies functions of hosts in the infrastructure.
- Targeted Detection: Detects dynamically generated domain (DGA) names to alert on potentially malicious sites.
- False Alarm Control: Adjusts scoring contribution of triggered statistical rules to minimize false alarms.