IBM® QRadar User Behavior Analytics (UBA) is an app that provides early visibility to insider threats. It is an extension of the IBM QRadar Security Intelligence Platform that analyzes the usage patterns of insiders to determine if their credentials or systems have been compromised by cybercriminals.

The app features a user-centric dashboard showing risky users by name and their anomalous activities, along with QRadar associated incidents. A single mouse click adds suspects to a watch list or permits a text-based annotation to explain the observations, or drill down into underlying log and flow data.

Fine-grained machine learning algorithms can detect when users alter their normal application practices, behave differently from peers, or perform invalid sequences of operations.