Home
Products
LogEase SIEM Platform
LogEase UEBA
LogEase LAS
Observability Platform
AIOps Platform
Log Management Platform
LogEase SOAR
LogEase SecOps AI Assistant
Resources
Customer Stories
Documentation
Videos
Ebooks
Company
About Us
Contact Us
Blog
Copilot
EN
简体中文
English
Let's Talk
PRODUCT INTRODUCTION
LogEase UEBA leverages big data and machine learning to analyze various data sources like network traffic, security logs, and endpoint activities, identifying and alerting on behavioral anomalies, helping users rapidly pinpoint and address internal risks with effective response measures.
FUNCTIONAL MODULES
Comprehensive Log Data Collection
Unified Threat Detection and Management
Log collection from various sources such as security devices, network devices, endpoint, DLP, VPN, and applications.

Provides million-level EPS (Event Per Second) log stream processing capabilities, PB-level, and second-level log traceability.
Over 200 behavior analysis rules are built-in to effectively detect internal exceptions or violations, including compromised accounts, employee behavior exceptions, and internal data leakage.

Through the rule configuration interface, real-time and historical data can be aggregated, correlated, and compared to achieve abnormal user behavior and internal threats modeling.

Threat alerts are displayed in a centralized manner. Security team can further analyze and confirm the alerts or respond through third-party security devices/systems to deal with relevant users (lock accounts or send tickets, etc.).
Risk Visualization
Centralized User Tagging and Portrait
Peer Group Risk View: Displays the total number of alerted users, alert counts, trends, and rankings per department, showcasing the threat profile in peer group dimension.

Individual Risk View: Query personal information, alert overview, trends, and tags using the user’s unique identifier for centralized risk information.
Static and dynamic tags are combined to analyze user behaviors, summarize tags and portraits, establish a normal behavior baseline, and aid in detecting abnormal behavior.
Identity Center
Risk Scoring
Acquire user information via manual creation, CSV import, and third-party system integration, providing identity data for UEBA modules and aiding user behavior analysis through correlation.
Customize risk scoring by assigning point deductions for violations. The system calculates a 100-point risk score for each user, offering a clear and intuitive measure of their risk level based on behaviors.
User Behavior Analysis Models
High-frequency Behavior Analysis: User behavior is compared against historical baselines to identify significant deviations.

Rare Behavior Analysis: Abnormalities are flagged if uncommon behaviors occur, as normal office behaviors are typically repetitive.

Individual vs. Group Behavior Comparison: By comparing individual actions with those of the group, unusual behaviors within the same department can be detected.

Automated Behavior Discovery: Regular behaviors are reviewed for anomalies, such as scripting or scheduled bulk emails, to detect potential leaks.

Through the case management function, it promotes the closed loop of the security incident handling process, forms a multi-role and multi-user collaborative response, and supports the interfacing with user's internal ticketing system.
Full interface playbook layout.

Selects the corresponding playbook for responses according to the data source and matching conditions, such as the event type of SIEM/Posture platform, etc.

Automatically perform actions such as intelligence querying, IP blocking, account locking, sending work order, sending email, etc.

Interfaces APIs of Firewall, WAF, EDR, AD and other devices with SOAR.
Allows administrator to perform action auditing, any action performed by user and the related information will be recorded, including time, username, client IP, functional module, operation page, description, operation type and action.
PRODUCT FEATURES
Anomalous Behavior Capture
Real-time detection of abnormal behavior triggers immediate alerts, enabling security teams to conduct in-depth analysis and verification. They can leverage third party systems to respond, notify affected users, and initiate corrective actions upon confirmation.
Leveraging AI for Advanced Threat Detection
Equipped with the capability to detect threats through advanced machine learning models, our solution identifies internal threats that evade conventional security measures, significantly improving the detection and response to internal risks.
Risk Visualization
Using comprehensive visualization tools, we offer a detailed overview of security metrics. Violations by key users are consolidated into a single view, presenting risk scores and risk radar, and a timeline of behaviors, providing clear and actionable insights into potential threats.
User Profile
By combining static and dynamic tags, we analyze user behavior in depth, summarizing key behavioral tags and metrics. This creates a holistic view of user activities and builds a comprehensive user profile.
Risk Scoring
Analyzing alerts becomes challenging when there are numerous alert types, making it difficult to prioritize them. Moreover, it's challenging to intuitively evaluate a user's risk level. To address this, a risk scoring system has been implemented that assesses users based on alerts, user characteristics, alert timing, and target object features.
Anomalous Behavior Capture
Real-time detection of abnormal behavior triggers immediate alerts, enabling security teams to conduct in-depth analysis and verification. They can leverage third party systems to respond, notify affected users, and initiate corrective actions upon confirmation.
BENEFITS
Extensive Coverage of Behavioral Analysis Scenarios
● Traditional Solutions: Often fail to detect a significant number of violations and anomalies.
● LogEase Solution: Utilizes over 200 models to provide comprehensive alerts for a wide range of abnormal behaviors, ensuring that potential issues are both visible and actionable.
Flexible and Configurable Rule Models
● Traditional Solutions: Rely on fixed detection models, which can be slow to update and adapt to new scenarios.
● LogEase Solution: Offers zero-cost, near-instantaneous updates to detection models, allowing for rapid adaptation to new and emerging threats.
In-Depth Long-Term Analysis
● Traditional Solutions: Typically limited to analyzing behavioral data within a one week timeframe.
● LogEase Solution: Capable of analyzing data spanning several years, with no theoretical upper limit, enabling deep and thorough investigation of historical patterns and long-term trends in violation behavior.
LET'S ARRANGE A MEETING
Contact us and LogEase Support Team is here to answer it for you from Monday to Friday.
Email Support
contact@yottabyte.cn
Phone Support
+86 18611176014
WhatsApp
+86 18611176014
LEAVE US A MESSAGE
x
PRODUCT INTRODUCTION
LogEase UEBA leverages big data and machine learning to analyze various data sources like network traffic, security logs, and endpoint activities, identifying and alerting on behavioral anomalies, helping users rapidly pinpoint and address internal risks with effective response measures.
FUNCTIONAL MODULES
Comprehensive Log Data Collection
Log collection from various sources such as security devices, network devices, endpoint, DLP, VPN, and applications.

Provides million-level EPS (Event Per Second) log stream processing capabilities, PB-level, and second-level log traceability.
Unified Threat Detection and Management
Over 200 behavior analysis rules are built-in to effectively detect internal exceptions or violations, including compromised accounts, employee behavior exceptions, and internal data leakage.

Through the rule configuration interface, real-time and historical data can be aggregated, correlated, and compared to achieve abnormal user behavior and internal threats modeling.

Threat alerts are displayed in a centralized manner. Security team can further analyze and confirm the alerts or respond through third-party security devices/systems to deal with relevant users (lock accounts or send tickets, etc.).
Risk Visuaization
Peer Group Risk View: Displays the total number of alerted users, alert counts, trends, and rankings per department, showcasing the threat profile in peer group dimension.

Individual Risk View: Query personal information, alert overview, trends, and tags using the user’s unique identifier for centralized risk information.
Centralized User Tagging and Portrait
Static and dynamic tags are combined to analyze user behaviors, summarize tags and portraits, establish a normal behavior baseline, and aid in detecting abnormal behavior.
Identity Center
Acquire user information via manual creation, CSV import, and third-party system integration, providing identity data for UEBA modules and aiding user behavior analysis through correlation.
Risk Scoring
Customize risk scoring by assigning point deductions for violations. The system calculates a 100-point risk score for each user, offering a clear and intuitive measure of their risk level based on behaviors.

User Behavior Analysis Models
High-frequency Behavior Analysis: User behavior is compared against historical baselines to identify significant deviations.

Rare Behavior Analysis: Abnormalities are flagged if uncommon behaviors occur, as normal office behaviors are typically repetitive.

Individual vs. Group Behavior Comparison: By comparing individual actions with those of the group, unusual behaviors within the same department can be detected.

Automated Behavior Discovery: Regular behaviors are reviewed for anomalies, such as scripting or scheduled bulk emails, to detect potential leaks.
PRODUCT FEATURES
Anomalous Behavior Capture
Real-time detection of abnormal behavior triggers immediate alerts, enabling security teams to conduct in-depth analysis and verification. They can leverage third party systems to respond, notify affected users, and initiate corrective actions upon confirmation.
Leveraging AI for Advanced Threat Detection
Equipped with the capability to detect threats through advanced machine learning models, our solution identifies internal threats that evade conventional security measures, significantly improving the detection and response to internal risks.
Risk Visualization
Using comprehensive visualization tools, we offer a detailed overview of security metrics. Violations by key users are consolidated into a single view, presenting risk scores and risk radar, and a timeline of behaviors, providing clear and actionable insights into potential threats.
User Profile
By combining static and dynamic tags, we analyze user behavior in depth, summarizing key behavioral tags and metrics. This creates a holistic view of user activities and builds a comprehensive user profile.
Risk Scoring
Analyzing alerts becomes challenging when there are numerous alert types, making it difficult to prioritize them. Moreover, it's challenging to intuitively evaluate a user's risk level. To address this, a risk scoring system has been implemented that assesses users based on alerts, user characteristics, alert timing, and target object features.
Anomalous Behavior Capture
Real-time detection of abnormal behavior triggers immediate alerts, enabling security teams to conduct in-depth analysis and verification. They can leverage third party systems to respond, notify affected users, and initiate corrective actions upon confirmation.
BENEFITS
Flexible and Configurable Rule Models
● Traditional Solutions: Often fail to detect a significant number of violations and anomalies.
● LogEase Solution: Utilizes over 200 models to provide comprehensive alerts for a wide range of abnormal behaviors, ensuring that potential issues are both visible and actionable.
Comprehensive Threat Investigation
● Traditional Solutions: Rely on fixed detection models, which can be slow to update and adapt to new scenarios.
● LogEase Solution: Offers zero-cost, near-instantaneous updates to detection models, allowing for rapid adaptation to new and emerging threats.
In-Depth Long-Term Analysis
● Traditional Solutions: Typically limited to analyzing behavioral data within a one week timeframe.
● LogEase Solution: Capable of analyzing data spanning several years, with no theoretical upper limit, enabling deep and thorough investigation of historical patterns and long-term trends in violation behavior.
LET'S ARRANGE A MEETING
Contact us and LogEase Support Team is here to answer it for you from Monday to Friday.
Email Support
contact@yottabyte.cn
Phone Support
+86 18611176014
WhatsApp
+86 18611176014
LEAVE US A MESSAGE
x