sk Skill · mukul975
detecting-insider-threat-with-ueba
Implement User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and alert on insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access. Use when building or tuning a UEBA pipeline rather than a one-off manual hunt.
Open on skills.sh ↗read 2026-09-17
- installs 8w
- 0
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
siemmachine-learningbehavior-analyticsanomaly-detectionPythonelasticsearchinsider-threatueba
- Host repository
- mukul975/Anthropic-Cybersecurity-Skills
- Version
- 1.0
- Licence
- Apache-2.0
- Host stars
- 33k
- Host language
- Python