Behavioural Analytics After Its Standalone Market Disappeared
How CodoraTech is funded: CodoraTech is supported by advertising and, in some articles, by affiliate links. Where an article contains affiliate links, we say so at the top of that article.
Gartner defined user and entity behaviour analytics in an April 2018 market guide as solutions that use analytics to build the standard profiles and behaviors of users and entities across time and peer group horizons. In the same document it predicted the category would stop existing as a standalone market by 2021 and would instead be embedded in 80 percent of threat detection and incident prioritisation products by 2022. That is roughly what happened. The technique is now everywhere and almost never bought by name, which makes its published evidence base unusually hard to inspect.
The market Gartner said would stop existing
The 2018 Market Guide for User and Entity Behavior Analytics, catalogue number G00349450, was written by Gorka Sadowski, Avivah Litan, Toby Bussa and Tricia Phillips and dated 23 April 2018. Its list of representative standalone vendors names Bay Dynamics, Exabeam, Gurucul, HPE Aruba’s Niara product, Interset, LogRhythm, Securonix and Splunk’s Caspida-derived UBA.
Two of those eight merged. SDxCentral reported that LogRhythm and Exabeam announced their combination on 15 May 2024, six years after Thoma Bravo became LogRhythm’s majority investor with that intention stated. Forrester analysts quoted in the same report expected further consolidation and rising pressure from XDR vendors, and noted that Exabeam had high-quality user behaviour analytics but declining popularity because of a lack of completeness in areas such as SIEM and SOAR.
One consequence deserves stating before any of the numbers below. No public, independently verified deployment outcome for a named end-user organisation was located for this article; the success stories that exist are hosted by the vendors whose products they describe. That absence is itself the finding.
What Microsoft documents its detections doing, and when they run
Microsoft Entra ID Protection is one of the few behavioural analytics products whose detection catalogue is published in full, which makes it describable without guesswork. Its documented behavioural detections include:
- Unfamiliar sign-in properties, computed in real time, profiling past sign-in history against IP address, ASN, location, device, browser and tenant IP subnet, with new users held in a learning mode of at least five days before it activates
- Impossible travel and atypical travel, both offline detections computed after the sign-in has happened, with atypical travel requiring a learning period of 14 days or 10 logins
- Anomalous user activity, which baselines normal administrative behaviour and flags suspicious directory changes
- Suspicious browser, which identifies anomalous behaviour across multiple tenants and countries from a single browser
- Anomalous token, which Microsoft’s own documentation labels as having a higher false-positive rate at low and medium risk levels
Ninety-nine percent false positives, and what the researchers meant by it
Bushra A. Alahmadi, Louise Axon and Ivan Martinovic of the University of Oxford presented 99% False Positives: A Qualitative Study of SOC Analysts’ Perspectives on Security Alarms at the 31st USENIX Security Symposium in August 2022, drawing on interviews with 21 practitioners across seven security operations centres and a survey of 20 more.
The title comes from a practitioner, who said they know 99 percent of the alarms they generate are false positives but still have to look at them. Another put the ratio as one real threat in every hundred alerts investigated. The researchers themselves qualify this heavily, and the qualification should travel with the quote: most of what analysts call a false positive is a benign trigger, a real detection the organisation has decided to ignore for business reasons, not a tool error. The 99 percent is not a measured error rate for any product.
The volumes behind it are still real. Forty-five percent of analysts reported fewer than 5,000 alerts per day, while large enterprises running fewer than 20 analysts sometimes processed over 100,000. Only 10 percent of survey participants used machine-learning tooling, citing both that such platforms themselves generate many false alarms and the absence of accreditation for government deployment. One analyst’s objection to opaque scoring is the paper’s sharpest line: if you do not tell me the reason you fire, I cannot have really high respect for that.
Weakest against the insider it is sold to catch
Gartner’s own cautions in 2018 were blunter than the marketing that followed. Deployment, it wrote, can be more time-consuming and labor-intensive than what vendors promise, and it takes three to six months to get a UEBA initiative off the ground and tuned to deliver on the use cases.
Two further cautions go to the core of the technique. User and entity profiling and machine learning, Gartner wrote, are still not sufficiently proven when it comes to detecting suspicious behavior among privileged users, developers and knowledgeable insiders, which is precisely the population the category is sold to watch. And a given user or peer group can be bad from the start of profiling, so that ongoing bad behavior will not be noted as anomalous. A baseline learned from a compromised environment encodes the compromise as normal.
The most consequential recent US insider case turned on human reporting, not analytics. The US Air Force Inspector General report of 11 December 2023 on the Jack Teixeira disclosures, as summarised by Lawfare, found that the 102nd Intelligence Wing showed a lackluster culture regarding the security of classified information and that unit members knew of four documented instances of improper handling or access but did not report them, fearing an overreaction. The Inspector General concluded that had those instances been reported to the proper officials, the amount of leaked information could have been greatly reduced.
Cost figures in this space are almost all sponsored. The 2025 Cost of Insider Risks Global Report, run by the Ponemon Institute and sponsored by DTEX Systems, which sells insider risk software, puts the average annual cost of insider threats at 17.4 million dollars against 16.2 million in 2023. Its finding that 65 percent of organisations with such programmes called them the only strategy that pre-empted a breach is a customer self-report, not a measured outcome.
A 32 million euro fine, and a red line in the AI Act
Gartner flagged the legal exposure in 2018, warning that monitoring trusted insiders raises privacy and regulatory issues for organizations, especially those in jurisdictions under tight regulatory schemes.
CNBC reported in January 2024 that France’s data protection authority, the CNIL, fined Amazon France Logistique 32 million euros over an employee monitoring system it judged excessively intrusive, a case centred on scanner-derived productivity indicators and video surveillance in warehouses.
The EU AI Act adds a categorical prohibition rather than a proportionality test. Article 5(1)(f) bars AI systems that infer the emotions of a natural person in the workplace or in education, including in hiring and admissions, excepting only strictly medical or safety purposes, narrowly interpreted, which does not cover general wellness monitoring such as stress detection. The Future of Privacy Forum’s analysis notes the boundary that matters here: the prohibition attaches to inference from biometric data specifically, not to behavioural analysis in general.
The oldest objection is not about data protection at all. On 6 January 2016, 22 organisations including the ACLU, the American Library Association, the Freedom of the Press Foundation, the Government Accountability Project, the National Whistleblower Center, the Niskanen Center, OpenTheGovernment.org, PEN American Center, the Project On Government Oversight, Public Citizen and the R Street Institute wrote to the Intelligence Community Inspector General asking for an investigation of the federal Insider Threat Program. Their central complaint was that training materials characterised the NSA whistleblower Thomas Drake as an insider threat alongside the Fort Hood shooter Nidal Hasan and the Navy Yard killer Aaron Alexis, and that the programme’s definitions failed to distinguish between those who want to fix problems from those who wish to do harm.
The honest position, then. Behavioural analytics is useful for investigation and triage, mostly after the fact rather than as a block. Its own analyst house documented a long tuning cost and a weakness against the privileged insider it is marketed against, its published outcome evidence is vendor-controlled, and the question the 2016 letter raised, of who counts as a threat when a system watches for deviation from normal, now carries fines.
Sources: Gartner, Market Guide for User and Entity Behavior Analytics (G00349450) · SDxCentral · USENIX Security Symposium 2022 (Alahmadi, Axon and Martinovic) · Microsoft Entra ID Protection documentation · CNBC