Home NDR Monitoring DNS Shield UEBA Analytics RECON Scanner Blog Company Deutsch (DE) Contact

Detect attacks
before damage is done.

UEBA: User & Entity Behavior Analytics against insider threats & ransomware

IRONATE UEBA monitors 6 platforms simultaneously: Windows and Linux endpoints, Microsoft 365, Azure Cloud, network devices and applications, correlated with 42+ MITRE ATT&CK techniques and 70+ behavioral metrics. On-device detection in milliseconds. No cloud dependency, full data sovereignty.

42+
MITRE ATT&CK techniques covered
6
Platforms in one solution
70+
Behavioral metrics monitored
43
Auto-response action types

UEBA Analytics in Action

See how IRONATE UEBA uncovers insider threats and anomalies.

Unique Differentiator

Detection directly on the endpoint: not in the cloud.

Conventional UEBA systems collect raw data, ship it to the cloud and detect threats only minutes later. IRONATE UEBA works differently: the detection logic runs directly on the Windows and Linux endpoint. The result: detection in milliseconds, even without a network connection.

Only alerts and aggregates are transmitted to the backend, never raw data. Your sensitive operational data never leaves the device. No other UEBA system on the market offers this combination of on-device speed and data protection.

bolt

Milliseconds instead of minutes

Detection on-device, before the next process starts

cloud_off

No raw data sent to the cloud

Only alerts are transmitted, FADP-compliant by architecture

wifi_off

Works without a network connection

Local buffering and detection even in offline operation

stop_circle

Automatic process kill (optional)

The agent can terminate a suspicious process immediately, unique in the market

compare_arrows

On-Device vs. Cloud UEBA

Feature IRONATE UEBA Cloud UEBA
Detection latency Milliseconds Minutes
Raw data leaves the network No Yes
Offline detection Yes No
On-device process kill Yes No
US jurisdiction / CLOUD Act No Yes
German-language interface Yes (CH) No

20+ attack scenarios detected.

enhanced_encryption

Ransomware activity

Detects encryption patterns by correlating anomalous file, registry and process activity: evaluated as a complete pipeline, not as isolated events.

key_off

Credential dumping

LSASS memory access, DCSync, Kerberoasting and AS-REP roasting are detected the moment they occur: with no delay.

group_remove

Insider threats

Peer group comparison flags suspicious administrators even when their activity would look unremarkable on its own.

no_accounts

Compromised accounts

Identifies account takeovers through behavioral deviations: including impossible travel, new countries and conditional access bypass in M365/Entra.

cloud_upload

Data exfiltration

Mass downloads from SharePoint/OneDrive, anomalous FTP/SFTP transfers, large-scale NAS read access and BEC forwarding rules in Exchange are detected.

schedule

Unusual access times

Alerts on system access outside typical working hours: by automatically learning individual weekly and daily patterns.

security

Privilege escalation

Detects domain admin group joins, GPO manipulation, sudo/su escalation on Linux and unauthorized role assignments in Azure.

robot_2

Service account abuse

Suspicious PowerShell executions, obfuscated code and unusual service account activity are detected through behavioral analysis.

cloud_off

Azure cloud sabotage

Mass deletion of VMs, storage containers, key vaults and Intune device wipes are detected as suspicious cloud activity.

automation

Power Automate abuse

Unauthorized flows that forward sensitive data or execute automated actions are detected in Microsoft 365.

dns

C2 & DGA detection

C2 beaconing and DGA domains are detected via a dual Shannon entropy threshold and DNS query frequency analysis: even obfuscated C2 channels.

web_asset_off

Webshell & lateral movement

Web shell drops, process injections, named pipe abuse and remote thread creation for lateral movement are detected.

Why IRONATE UEBA?

What Exabeam, Securonix and Sentinel cannot do.

Enterprise UEBA used to be cloud-only and expensive. IRONATE UEBA breaks this pattern with on-device detection, Swiss data sovereignty and a fully German-language interface built for DACH-based teams.

Feature IRONATE UEBA Exabeam Securonix Microsoft Sentinel
On-device detection (milliseconds)check_circlecancelcancelcancel
Automatic on-device process killcheck_circlecancelcancelcancel
On-premises / no cloud requirementcheck_circlecancelcancelcancel
FADP/GDPR / no CLOUD Actcheck_circlecancelcancelcancel
Local AI analyst (no cloud LLM)check_circlecancelcancelhelp
German-language interface (CH)check_circlecancelcancelhelp
Integrated memory forensicscheck_circlehelphelpcancel
Swiss made & local supportcheck_circlecancelcancelcancel
Pricing modelCHF 0.70–7.00
per entity/mo.
6-figure USD/year
(minimum commit)
6-figure USD/year
(minimum commit)
Usage-based
(US cloud)

help = limited or add-on required

Business Benefits

Why UEBA is indispensable

60% of all data loss traces back to insider threats. UEBA detects the invisible risk before it turns into a million-franc loss.

psychology

Behavior instead of rules: zero-day ready

Traditional SIEM rules only detect known patterns. IRONATE UEBA learns the individual behavior of every user and every entity and detects deviations that rule-based systems miss, including zero-day insider attacks and novel malware.

trending_down

Drastically fewer false positives

Alert fatigue paralyzes security teams. IRONATE UEBA substantially reduces false positives through context-aware risk scoring, peer group comparison and adaptive baselines, so your team spends its time on real threats.

admin_panel_settings

Full visibility into privileged access

Admin accounts are attackers' primary target. IRONATE UEBA monitors all privileged access in real time, across endpoints, M365, Azure and Active Directory simultaneously.

timer

Operational in 72 hours

No months of tuning. IRONATE UEBA starts learning immediately and delivers the first actionable insights after just 72 hours, with seamless integration with M365 Entra, Active Directory and network devices.

RansomProtect

Stop ransomware before encryption starts.

IRONATE UEBA includes a specialized RansomProtect engine that evaluates an entire encryption pipeline as a whole instead of just matching individual IOCs.

enhanced_encryption

Mass Encryption Detection

Detects suddenly anomalous file activity patterns, mass file creation, anomalies in extension distribution and mass deletes as typical encryption signals.

build

Pipeline Correlation

Multi-stage behavioral correlation across several simultaneous signals that characterize an encryption pipeline, instead of looking at isolated single events.

policy

AV/EDR Tampering Protection

Detects the systematic termination of AV/EDR processes, a classic pre-encryption step of modern ransomware families.

memory

Integrated Memory Forensics

Analyzes process memory for injected code, shellcode patterns and DLL manipulation, directly in the platform, without an external forensics tool.

stop_circle

Auto-Kill (optional)

On a critical verdict, the agent can terminate the suspicious process immediately, with optional backend validation against false positives. Unique in the market.

link

Threat Chain Correlation

Related alerts are automatically grouped into multi-stage attack chains, mapped to MITRE ATT&CK phases and assigned an aggregated risk score.

360° Data Sources

Six layers. One platform.

IRONATE UEBA correlates telemetry from endpoints, cloud identity, Azure, network and applications, and detects attacks that only become visible through correlation across platform boundaries.

computer

Windows Endpoint Agent

Native agent with deep system integration. Detection runs locally on the device, only alerts are transmitted.

  • checkWindows Server 2016–2025, Win 10/11
  • checkProcess, file, registry, network and DNS telemetry
  • checkMemory access and named pipe monitoring
  • checkBuffering during network outages
terminal

Linux Endpoint Agent

eBPF/syscall-based, kernel-level visibility without a kernel module. Supports Ubuntu, Debian, RHEL, CentOS.

  • checkKernel 4.15+ compatible
  • checkPrivilege escalation: sudo, su, pkexec, SUID/SGID
  • checkProcess tree reconstruction from kernel state
  • checkLocal buffering on connection loss
cloud

Microsoft 365 / Entra ID

Direct connection to Microsoft cloud APIs. Detects identity attacks, data exfiltration and configuration abuse.

  • checkSign-in anomalies, impossible travel, conditional access bypass
  • checkSharePoint/OneDrive mass download, Exchange BEC
  • checkTeams, Intune device wipes, Power Automate
  • checkMulti-tenant capable with encrypted credentials
hub

Azure Cloud

Azure Activity Log and resource monitoring. Detects cloud sabotage and unauthorized infrastructure changes.

  • checkMass deletion of VMs, storage, key vaults
  • checkUnauthorized role assignments and policy changes
  • checkAzure Monitor diagnostic logs integration
  • checkVM management anomalies
router

Network Syslog

Native parsers for Swiss enterprise platforms, UDP/TCP. Detects anomalies directly from the raw log.

  • checkFortinet FortiGate (VPN, traffic, firewall deny)
  • checkPalo Alto PAN-OS (GlobalProtect, Threat)
  • checkCisco ASA/FTD (VPN, firewall)
  • checkNetApp ONTAP & StorageGRID (NFS/CIFS)
folder_open

Application Logs

Prebuilt and configurable parsers for application logs, without installing an agent on the server.

  • checkFileZilla & SFTPGo (FTP/SFTP activity)
  • checkIIS, Apache, Nginx (HTTP access logs)
  • checkCustom parsers for proprietary applications
  • checkMulti-format timestamp normalization
Detection Engine

Multiple models. Per entity. In parallel.

No single-algorithm bias: every asset is evaluated simultaneously by several complementary detection models, combined with Sigma rules and instant detection for critical attack patterns.

show_chart

Adaptive Baselines

Automatically learns the normal behavior of every entity.

center_focus_strong

Real-Time Deviation

Instant alerts on atypical behavior.

trending_up

Drift Detection

Detects gradual behavioral changes.

calendar_view_week

Weekly & Daily Patterns

Accounts for typical working-hour rhythms.

shield

Outlier-Resistant Scoring

Stable against individual outliers in normal behavior.

timeline

Long-Term Trend Analysis

Keeps changes over time in view.

visibility

Zero-Day Detection

New, unknown entities detected immediately.

groups

Peer Group Comparison

K-means clustering automatically forms comparison groups by activity profile, without manual categorization.

bolt

Instant detection of critical patterns

These attack patterns are detected immediately, without a statistical baseline:

  • DCSync: Domain controller replication by unauthorized accounts
  • Kerberoasting: Service ticket cracking attempts
  • AS-REP Roasting: Pre-authentication bypass
  • Privileged Group Joins: Additions to domain/enterprise admin groups
  • Webshell Drop: Web server processes writing executable scripts
  • Database Shell Spawn: DB servers spawning shell processes
  • Process Tampering (EID 25): Process hollowing, herpaderping and ghosting, detected via Sysmon Event 25
  • ADS Detection (EID 15): Alternate Data Streams on NTFS as a hidden exfiltration channel
  • Kerberos Pre-Auth Failures (Sec 4771): Mass failures as a brute-force and password-spray indicator
manage_search

Sigma rules, IOC feeds & retro scan

Industry-standard detection rules plus Ironate extensions:

  • YAML-based Sigma rules (community + privately curated)
  • Custom rule editor in the platform
  • IOC feed matching: IPs, domains, hashes, URLs
  • Retro scan: Check historical data up to 90 days back against new IOC feeds
  • PowerShell obfuscation detection
  • Auto-learn whitelist: Legitimate anomalies are automatically recognized and suppressed, fewer false positives without manual upkeep
  • C2 beaconing and DGA detection via DNS anomalies
smart_toy

Local AI analyst, your data never leaves the company

Optional AI assistant that runs entirely on your own hardware: alert triage, threat summarization and recommended actions in German, without your security data ever being transmitted to external services. Privacy by design.

Swiss & FADP-compliant
Automated Response

From alert to containment: in seconds.

43 predefined action types, an integrated playbook engine and a four-eyes principle for critical measures. No separate SOAR solution required.

shield_lock

Endpoint & Identity Containment

Immediate isolation of compromised hosts and accounts via enterprise APIs:

  • checkSophos Central (network isolation via XDR)
  • checkMicrosoft Defender for Endpoint (machine isolation)
  • checkCrowdStrike Falcon (RTR endpoint contain)
  • checkVMware NSX-T (dynamic firewall IP block)
  • checkAD LDAP & Entra ID (account disable, session revoke, MFA reset)
approval

Four-Eyes Principle & Audit Chain

Sensitive actions require a second approval, with a complete chain of evidence:

  • checkRequester ≠ approver enforced
  • checkConfigurable timeout behavior
  • checkComplete audit chain per approval
  • checkNotification via email, Teams or Slack
notifications_active

Notifications & Ticketing

Direct integration into your existing SecOps and ITSM tools:

  • checkMicrosoft Teams, Slack
  • checkServiceNow (automatic incident ticket)
  • checkJira, SMTP, generic JSON webhooks
  • check5 notification channels simultaneously
account_tree

Playbook Engine & Custom Modules

Conditional playbooks plus your own scripts for forensic snapshots:

  • check43 prebuilt action types
  • checkIf-then-else, loops, wait states
  • checkCustom modules (PowerShell / Python)
Compliance & Forensics

Compliant with NIS2, ISO 27001, FINMA & revDSG

Audit trail, retention policies, data subject rights and PDF reports are built-in platform features, not external add-ons.

history

Complete Audit Trail

Every action: login, alert status change, approval, isolation: is recorded with timestamp, user and context.

delete_sweep

Right to Erasure (Art. 17)

GDPR-compliant deletion of subject data via a built-in endpoint: consistent across all databases.

lock

AES-256 Encryption

Sensitive configuration values (API keys, OAuth secrets) are stored AES-256 encrypted with a separately manageable key.

picture_as_pdf

Compliance PDF Reports

Prebuilt templates for NIS2, ISO 27001, GDPR/revDSG and FINMA: exportable directly from the platform, weekly or monthly.

manage_search

Forensic depth, threat hunt & timeline reconstruction

Visual Threat Hunt

Visual query builder for manual threat hunting across all collected events.

Timeline Analysis

Reconstruction of the attack sequence from correlated alerts with MITRE ATT&CK phase mapping.

Process Tree Reconstruction

Parent-child visualization of malware execution chains as an interactive network graph.

Memory Dump Analysis

Integrated memory forensics for shellcode search and injected code, no separate tool required.

Transparent Pricing

UEBA Analytics Price List

Fair, volume-based pricing. The more entities you monitor, the lower the price per unit.

Number of EntitiesPrice in CHF
1 – 100CHF 7.00
101 – 300CHF 6.00
301 – 500CHF 4.00
501 – 1,000CHF 3.00
1,001 – 2,000CHF 2.00
2,001 – 4,000CHF 1.00
4,001 – 8,000CHF 0.80
8,001 – 12,000CHF 0.70

Prices per entity / month, excl. VAT. Custom terms for 12,000+ entities on request.

What is UEBA (User and Entity Behavior Analytics)?

UEBA (User and Entity Behavior Analytics) is a cybersecurity technology that analyzes the normal behavior of users, devices and applications and detects deviations as potential threats, even without known signatures.

Unlike rule-based SIEM systems, UEBA detects unknown threats (zero-day), because detection is based on behavioral deviations. This makes UEBA particularly effective against insider threats, compromised accounts and advanced ransomware attacks that deliberately evade security systems.

IRONATE UEBA goes beyond classic UEBA: with on-device detection on Windows and Linux endpoints, the system detects threats in milliseconds, directly on the device, without sending raw data to the cloud. 6 platforms are correlated in a single solution: endpoints, M365, Azure, network devices, FTP/web servers and custom applications.

As the only Swiss UEBA solution, IRONATE offers a fully German-language interface, a local AI analyst without cloud data transfer and compliance reports for NIS2, ISO 27001, FINMA and the revised Swiss Data Protection Act (revDSG), built in, not as an add-on.

Typical use cases

Insider threats
Detection of unusual activity by your own employees or partners, through peer group comparison even when the behavior looks unremarkable in isolation.
Compromised accounts & account takeover
Identifies account takeovers through behavioral deviations: logins from unknown locations, impossible travel, conditional access bypass or nighttime sign-ins.
Early ransomware detection
The RansomProtect engine correlates the entire encryption pipeline, from process anomalies and AV termination to mass file activity. Optionally, the agent stops the process autonomously.
Preventing data exfiltration
Mass downloads from SharePoint, anomalous FTP/SFTP transfers, large-scale NAS read access and BEC forwarding rules in Exchange are detected before data leaves the company.

Frequently asked questions about UEBA

What is UEBA and why do I need it?expand_more

UEBA analyzes the behavior of users and systems and detects deviations as potential threats, even without known signatures. Insider threats, compromised accounts and ransomware are detected before damage is done. Rule-based SIEM systems typically miss these attacks because they rely on known patterns.

What sets IRONATE UEBA apart from Exabeam, Securonix or Microsoft Sentinel?expand_more

IRONATE UEBA detects threats directly on the endpoint in milliseconds, not only after a cloud upload. The agent can stop a suspicious process autonomously, without a detour through a cloud platform. No other vendor combines on-device detection, automatic process kill, a local AI analyst and full on-premises data sovereignty. Add to that the only fully German-language interface for enterprise UEBA, plus Swiss support.

How quickly is IRONATE UEBA operational?expand_more

IRONATE UEBA is operational within 72 hours. No months of tuning: the platform starts learning immediately and delivers the first actionable insights after just a few days.

Which platforms are monitored?expand_more

Six platforms in one solution: Windows endpoints (agent), Linux endpoints (agent), Microsoft 365 / Entra ID (SharePoint, OneDrive, Exchange, Teams, Intune, Power Automate, Conditional Access), Azure Cloud (Activity Log, resource management), network devices via syslog (Fortinet, Palo Alto, Cisco, NetApp) and application logs (FTP, web servers, custom parsers).

How does IRONATE UEBA detect ransomware?expand_more

The RansomProtect engine correlates multi-stage behavioral signals: anomalous file activity, AV/EDR process termination, registry manipulation and suspicious process activity are evaluated as a complete encryption pipeline, not as isolated events. Optionally, the agent stops the process autonomously. Integrated memory forensics analyzes process dumps for shellcode and injected code.

Which automated response actions are available?expand_more

43 predefined action types: endpoint isolation (Sophos, Microsoft Defender, CrowdStrike, VMware NSX-T), identity lockout (AD LDAP, Entra ID, session revoke, MFA reset), notifications (Teams, Slack, email), ticketing (ServiceNow, Jira) and custom scripts (PowerShell / Python). Sensitive actions require the four-eyes principle with a complete audit chain.

Is there an IOC retro scan?expand_more

Yes. IRONATE UEBA offers a retro scan that checks historical data up to 90 days back against new IOC feeds and Sigma rules. After a threat feed is published, past activity can be checked for connections immediately.

Is IRONATE UEBA compliant with NIS2 and FINMA?expand_more

Yes. Prebuilt PDF report templates for NIS2, ISO 27001, GDPR/revDSG and FINMA. Complete audit trail, four-eyes principle, AES-256 encryption of sensitive configuration data and GDPR right to erasure (Art. 17) as a built-in platform feature. Development, operations and support exclusively from Switzerland.

Is there a local AI analyst?expand_more

Yes. IRONATE UEBA optionally offers an AI assistant that runs entirely on your own hardware, without any cloud dependency. Alert triage, threat summarization and recommended actions are generated in German, without your security data ever leaving the company network. Privacy by design, compliant with the Swiss Data Protection Act (FADP).