detecting-insider-threat-with-ueba
mukul975/Anthropic-Cybersecurity-Skills
This skill implements User and Entity Behavior Analytics (UEBA) using Elasticsearch/OpenSearch. It goes beyond static rules to build behavioral baselines (e.g., login times, data volume) for users and entities. By calculating anomaly scores and performing peer group analysis, it detects suspicious activities such as data exfiltration, privilege abuse, and unauthorized access, allowing organizations to proactively identify high-risk insider threats.