- Rich analytics to test threat hypotheses across any timeframe
- Automated search of historical data using IOC's from STIX and custom threat feeds
- Visualizations to highlight anomalies and significant interactions
- Significant activity monitored and tagged to assist with both hunting and investigations
- Profiles for users, systems and devices
- Access by SIEM, NAC systems, etc. via an open API
- Pre-packaged incident response playbooks
- Customer-measured 30 hours/investigation savings
- Automatic detection of other entities impacted by the attack
Aruba's User and Entity Behavior Analytics (UEBA) solution, Aruba IntroSpect, detects attacks by spotting small changes in behavior that are often indicative of attacks that have evaded traditional security defenses. Aruba IntroSpect integrates advanced AI-based machine learning (ML), pinpoint visualizations and instant forensic insight into a single solution, so attacks involving malicious, compromised or negligent users, systems and devices are found and remediated before they damage the operations and reputation of the organization.