Detect attacks
before damage is done.
UEBA: User & Entity Behavior Analytics against insider threats & ransomware
IRONATE UEBA monitors 6 platforms simultaneously: Windows and Linux endpoints, Microsoft 365, Azure Cloud, network devices and applications, correlated with 42+ MITRE ATT&CK techniques and 70+ behavioral metrics. On-device detection in milliseconds. No cloud dependency, full data sovereignty.
UEBA Analytics in Action
See how IRONATE UEBA uncovers insider threats and anomalies.
Detection directly on the endpoint: not in the cloud.
Conventional UEBA systems collect raw data, ship it to the cloud and detect threats only minutes later. IRONATE UEBA works differently: the detection logic runs directly on the Windows and Linux endpoint. The result: detection in milliseconds, even without a network connection.
Only alerts and aggregates are transmitted to the backend, never raw data. Your sensitive operational data never leaves the device. No other UEBA system on the market offers this combination of on-device speed and data protection.
Milliseconds instead of minutes
Detection on-device, before the next process starts
No raw data sent to the cloud
Only alerts are transmitted, FADP-compliant by architecture
Works without a network connection
Local buffering and detection even in offline operation
Automatic process kill (optional)
The agent can terminate a suspicious process immediately, unique in the market
On-Device vs. Cloud UEBA
20+ attack scenarios detected.
Ransomware activity
Detects encryption patterns by correlating anomalous file, registry and process activity: evaluated as a complete pipeline, not as isolated events.
Credential dumping
LSASS memory access, DCSync, Kerberoasting and AS-REP roasting are detected the moment they occur: with no delay.
Insider threats
Peer group comparison flags suspicious administrators even when their activity would look unremarkable on its own.
Compromised accounts
Identifies account takeovers through behavioral deviations: including impossible travel, new countries and conditional access bypass in M365/Entra.
Data exfiltration
Mass downloads from SharePoint/OneDrive, anomalous FTP/SFTP transfers, large-scale NAS read access and BEC forwarding rules in Exchange are detected.
Unusual access times
Alerts on system access outside typical working hours: by automatically learning individual weekly and daily patterns.
Privilege escalation
Detects domain admin group joins, GPO manipulation, sudo/su escalation on Linux and unauthorized role assignments in Azure.
Service account abuse
Suspicious PowerShell executions, obfuscated code and unusual service account activity are detected through behavioral analysis.
Azure cloud sabotage
Mass deletion of VMs, storage containers, key vaults and Intune device wipes are detected as suspicious cloud activity.
Power Automate abuse
Unauthorized flows that forward sensitive data or execute automated actions are detected in Microsoft 365.
C2 & DGA detection
C2 beaconing and DGA domains are detected via a dual Shannon entropy threshold and DNS query frequency analysis: even obfuscated C2 channels.
Webshell & lateral movement
Web shell drops, process injections, named pipe abuse and remote thread creation for lateral movement are detected.
What Exabeam, Securonix and Sentinel cannot do.
Enterprise UEBA used to be cloud-only and expensive. IRONATE UEBA breaks this pattern with on-device detection, Swiss data sovereignty and a fully German-language interface built for DACH-based teams.
| Feature | IRONATE UEBA | Exabeam | Securonix | Microsoft Sentinel |
|---|---|---|---|---|
| On-device detection (milliseconds) | check_circle | cancel | cancel | cancel |
| Automatic on-device process kill | check_circle | cancel | cancel | cancel |
| On-premises / no cloud requirement | check_circle | cancel | cancel | cancel |
| FADP/GDPR / no CLOUD Act | check_circle | cancel | cancel | cancel |
| Local AI analyst (no cloud LLM) | check_circle | cancel | cancel | help |
| German-language interface (CH) | check_circle | cancel | cancel | help |
| Integrated memory forensics | check_circle | help | help | cancel |
| Swiss made & local support | check_circle | cancel | cancel | cancel |
| Pricing model | CHF 0.70–7.00 per entity/mo. | 6-figure USD/year (minimum commit) | 6-figure USD/year (minimum commit) | Usage-based (US cloud) |
help = limited or add-on required
Why UEBA is indispensable
60% of all data loss traces back to insider threats. UEBA detects the invisible risk before it turns into a million-franc loss.
Behavior instead of rules: zero-day ready
Traditional SIEM rules only detect known patterns. IRONATE UEBA learns the individual behavior of every user and every entity and detects deviations that rule-based systems miss, including zero-day insider attacks and novel malware.
Drastically fewer false positives
Alert fatigue paralyzes security teams. IRONATE UEBA substantially reduces false positives through context-aware risk scoring, peer group comparison and adaptive baselines, so your team spends its time on real threats.
Full visibility into privileged access
Admin accounts are attackers' primary target. IRONATE UEBA monitors all privileged access in real time, across endpoints, M365, Azure and Active Directory simultaneously.
Operational in 72 hours
No months of tuning. IRONATE UEBA starts learning immediately and delivers the first actionable insights after just 72 hours, with seamless integration with M365 Entra, Active Directory and network devices.
Stop ransomware before encryption starts.
IRONATE UEBA includes a specialized RansomProtect engine that evaluates an entire encryption pipeline as a whole instead of just matching individual IOCs.
Mass Encryption Detection
Detects suddenly anomalous file activity patterns, mass file creation, anomalies in extension distribution and mass deletes as typical encryption signals.
Pipeline Correlation
Multi-stage behavioral correlation across several simultaneous signals that characterize an encryption pipeline, instead of looking at isolated single events.
AV/EDR Tampering Protection
Detects the systematic termination of AV/EDR processes, a classic pre-encryption step of modern ransomware families.
Integrated Memory Forensics
Analyzes process memory for injected code, shellcode patterns and DLL manipulation, directly in the platform, without an external forensics tool.
Auto-Kill (optional)
On a critical verdict, the agent can terminate the suspicious process immediately, with optional backend validation against false positives. Unique in the market.
Threat Chain Correlation
Related alerts are automatically grouped into multi-stage attack chains, mapped to MITRE ATT&CK phases and assigned an aggregated risk score.
Six layers. One platform.
IRONATE UEBA correlates telemetry from endpoints, cloud identity, Azure, network and applications, and detects attacks that only become visible through correlation across platform boundaries.
Windows Endpoint Agent
Native agent with deep system integration. Detection runs locally on the device, only alerts are transmitted.
- checkWindows Server 2016–2025, Win 10/11
- checkProcess, file, registry, network and DNS telemetry
- checkMemory access and named pipe monitoring
- checkBuffering during network outages
Linux Endpoint Agent
eBPF/syscall-based, kernel-level visibility without a kernel module. Supports Ubuntu, Debian, RHEL, CentOS.
- checkKernel 4.15+ compatible
- checkPrivilege escalation: sudo, su, pkexec, SUID/SGID
- checkProcess tree reconstruction from kernel state
- checkLocal buffering on connection loss
Microsoft 365 / Entra ID
Direct connection to Microsoft cloud APIs. Detects identity attacks, data exfiltration and configuration abuse.
- checkSign-in anomalies, impossible travel, conditional access bypass
- checkSharePoint/OneDrive mass download, Exchange BEC
- checkTeams, Intune device wipes, Power Automate
- checkMulti-tenant capable with encrypted credentials
Azure Cloud
Azure Activity Log and resource monitoring. Detects cloud sabotage and unauthorized infrastructure changes.
- checkMass deletion of VMs, storage, key vaults
- checkUnauthorized role assignments and policy changes
- checkAzure Monitor diagnostic logs integration
- checkVM management anomalies
Network Syslog
Native parsers for Swiss enterprise platforms, UDP/TCP. Detects anomalies directly from the raw log.
- checkFortinet FortiGate (VPN, traffic, firewall deny)
- checkPalo Alto PAN-OS (GlobalProtect, Threat)
- checkCisco ASA/FTD (VPN, firewall)
- checkNetApp ONTAP & StorageGRID (NFS/CIFS)
Application Logs
Prebuilt and configurable parsers for application logs, without installing an agent on the server.
- checkFileZilla & SFTPGo (FTP/SFTP activity)
- checkIIS, Apache, Nginx (HTTP access logs)
- checkCustom parsers for proprietary applications
- checkMulti-format timestamp normalization
Multiple models. Per entity. In parallel.
No single-algorithm bias: every asset is evaluated simultaneously by several complementary detection models, combined with Sigma rules and instant detection for critical attack patterns.
Adaptive Baselines
Automatically learns the normal behavior of every entity.
Real-Time Deviation
Instant alerts on atypical behavior.
Drift Detection
Detects gradual behavioral changes.
Weekly & Daily Patterns
Accounts for typical working-hour rhythms.
Outlier-Resistant Scoring
Stable against individual outliers in normal behavior.
Long-Term Trend Analysis
Keeps changes over time in view.
Zero-Day Detection
New, unknown entities detected immediately.
Peer Group Comparison
K-means clustering automatically forms comparison groups by activity profile, without manual categorization.
Instant detection of critical patterns
These attack patterns are detected immediately, without a statistical baseline:
- •DCSync: Domain controller replication by unauthorized accounts
- •Kerberoasting: Service ticket cracking attempts
- •AS-REP Roasting: Pre-authentication bypass
- •Privileged Group Joins: Additions to domain/enterprise admin groups
- •Webshell Drop: Web server processes writing executable scripts
- •Database Shell Spawn: DB servers spawning shell processes
- •Process Tampering (EID 25): Process hollowing, herpaderping and ghosting, detected via Sysmon Event 25
- •ADS Detection (EID 15): Alternate Data Streams on NTFS as a hidden exfiltration channel
- •Kerberos Pre-Auth Failures (Sec 4771): Mass failures as a brute-force and password-spray indicator
Sigma rules, IOC feeds & retro scan
Industry-standard detection rules plus Ironate extensions:
- •YAML-based Sigma rules (community + privately curated)
- •Custom rule editor in the platform
- •IOC feed matching: IPs, domains, hashes, URLs
- •Retro scan: Check historical data up to 90 days back against new IOC feeds
- •PowerShell obfuscation detection
- •Auto-learn whitelist: Legitimate anomalies are automatically recognized and suppressed, fewer false positives without manual upkeep
- •C2 beaconing and DGA detection via DNS anomalies
Local AI analyst, your data never leaves the company
Optional AI assistant that runs entirely on your own hardware: alert triage, threat summarization and recommended actions in German, without your security data ever being transmitted to external services. Privacy by design.
From alert to containment: in seconds.
43 predefined action types, an integrated playbook engine and a four-eyes principle for critical measures. No separate SOAR solution required.
Endpoint & Identity Containment
Immediate isolation of compromised hosts and accounts via enterprise APIs:
- checkSophos Central (network isolation via XDR)
- checkMicrosoft Defender for Endpoint (machine isolation)
- checkCrowdStrike Falcon (RTR endpoint contain)
- checkVMware NSX-T (dynamic firewall IP block)
- checkAD LDAP & Entra ID (account disable, session revoke, MFA reset)
Four-Eyes Principle & Audit Chain
Sensitive actions require a second approval, with a complete chain of evidence:
- checkRequester ≠ approver enforced
- checkConfigurable timeout behavior
- checkComplete audit chain per approval
- checkNotification via email, Teams or Slack
Notifications & Ticketing
Direct integration into your existing SecOps and ITSM tools:
- checkMicrosoft Teams, Slack
- checkServiceNow (automatic incident ticket)
- checkJira, SMTP, generic JSON webhooks
- check5 notification channels simultaneously
Playbook Engine & Custom Modules
Conditional playbooks plus your own scripts for forensic snapshots:
- check43 prebuilt action types
- checkIf-then-else, loops, wait states
- checkCustom modules (PowerShell / Python)
Compliant with NIS2, ISO 27001, FINMA & revDSG
Audit trail, retention policies, data subject rights and PDF reports are built-in platform features, not external add-ons.
Complete Audit Trail
Every action: login, alert status change, approval, isolation: is recorded with timestamp, user and context.
Right to Erasure (Art. 17)
GDPR-compliant deletion of subject data via a built-in endpoint: consistent across all databases.
AES-256 Encryption
Sensitive configuration values (API keys, OAuth secrets) are stored AES-256 encrypted with a separately manageable key.
Compliance PDF Reports
Prebuilt templates for NIS2, ISO 27001, GDPR/revDSG and FINMA: exportable directly from the platform, weekly or monthly.
Forensic depth, threat hunt & timeline reconstruction
Visual Threat Hunt
Visual query builder for manual threat hunting across all collected events.
Timeline Analysis
Reconstruction of the attack sequence from correlated alerts with MITRE ATT&CK phase mapping.
Process Tree Reconstruction
Parent-child visualization of malware execution chains as an interactive network graph.
Memory Dump Analysis
Integrated memory forensics for shellcode search and injected code, no separate tool required.
UEBA Analytics Price List
Fair, volume-based pricing. The more entities you monitor, the lower the price per unit.
| Number of Entities | Price in CHF |
|---|---|
| 1 – 100 | CHF 7.00 |
| 101 – 300 | CHF 6.00 |
| 301 – 500 | CHF 4.00 |
| 501 – 1,000 | CHF 3.00 |
| 1,001 – 2,000 | CHF 2.00 |
| 2,001 – 4,000 | CHF 1.00 |
| 4,001 – 8,000 | CHF 0.80 |
| 8,001 – 12,000 | CHF 0.70 |
Prices per entity / month, excl. VAT. Custom terms for 12,000+ entities on request.
What is UEBA (User and Entity Behavior Analytics)?
UEBA (User and Entity Behavior Analytics) is a cybersecurity technology that analyzes the normal behavior of users, devices and applications and detects deviations as potential threats, even without known signatures.
Unlike rule-based SIEM systems, UEBA detects unknown threats (zero-day), because detection is based on behavioral deviations. This makes UEBA particularly effective against insider threats, compromised accounts and advanced ransomware attacks that deliberately evade security systems.
IRONATE UEBA goes beyond classic UEBA: with on-device detection on Windows and Linux endpoints, the system detects threats in milliseconds, directly on the device, without sending raw data to the cloud. 6 platforms are correlated in a single solution: endpoints, M365, Azure, network devices, FTP/web servers and custom applications.
As the only Swiss UEBA solution, IRONATE offers a fully German-language interface, a local AI analyst without cloud data transfer and compliance reports for NIS2, ISO 27001, FINMA and the revised Swiss Data Protection Act (revDSG), built in, not as an add-on.
Typical use cases
- Insider threats
- Detection of unusual activity by your own employees or partners, through peer group comparison even when the behavior looks unremarkable in isolation.
- Compromised accounts & account takeover
- Identifies account takeovers through behavioral deviations: logins from unknown locations, impossible travel, conditional access bypass or nighttime sign-ins.
- Early ransomware detection
- The RansomProtect engine correlates the entire encryption pipeline, from process anomalies and AV termination to mass file activity. Optionally, the agent stops the process autonomously.
- Preventing data exfiltration
- Mass downloads from SharePoint, anomalous FTP/SFTP transfers, large-scale NAS read access and BEC forwarding rules in Exchange are detected before data leaves the company.
Frequently asked questions about UEBA
What is UEBA and why do I need it?expand_more
UEBA analyzes the behavior of users and systems and detects deviations as potential threats, even without known signatures. Insider threats, compromised accounts and ransomware are detected before damage is done. Rule-based SIEM systems typically miss these attacks because they rely on known patterns.
What sets IRONATE UEBA apart from Exabeam, Securonix or Microsoft Sentinel?expand_more
IRONATE UEBA detects threats directly on the endpoint in milliseconds, not only after a cloud upload. The agent can stop a suspicious process autonomously, without a detour through a cloud platform. No other vendor combines on-device detection, automatic process kill, a local AI analyst and full on-premises data sovereignty. Add to that the only fully German-language interface for enterprise UEBA, plus Swiss support.
How quickly is IRONATE UEBA operational?expand_more
IRONATE UEBA is operational within 72 hours. No months of tuning: the platform starts learning immediately and delivers the first actionable insights after just a few days.
Which platforms are monitored?expand_more
Six platforms in one solution: Windows endpoints (agent), Linux endpoints (agent), Microsoft 365 / Entra ID (SharePoint, OneDrive, Exchange, Teams, Intune, Power Automate, Conditional Access), Azure Cloud (Activity Log, resource management), network devices via syslog (Fortinet, Palo Alto, Cisco, NetApp) and application logs (FTP, web servers, custom parsers).
How does IRONATE UEBA detect ransomware?expand_more
The RansomProtect engine correlates multi-stage behavioral signals: anomalous file activity, AV/EDR process termination, registry manipulation and suspicious process activity are evaluated as a complete encryption pipeline, not as isolated events. Optionally, the agent stops the process autonomously. Integrated memory forensics analyzes process dumps for shellcode and injected code.
Which automated response actions are available?expand_more
43 predefined action types: endpoint isolation (Sophos, Microsoft Defender, CrowdStrike, VMware NSX-T), identity lockout (AD LDAP, Entra ID, session revoke, MFA reset), notifications (Teams, Slack, email), ticketing (ServiceNow, Jira) and custom scripts (PowerShell / Python). Sensitive actions require the four-eyes principle with a complete audit chain.
Is there an IOC retro scan?expand_more
Yes. IRONATE UEBA offers a retro scan that checks historical data up to 90 days back against new IOC feeds and Sigma rules. After a threat feed is published, past activity can be checked for connections immediately.
Is IRONATE UEBA compliant with NIS2 and FINMA?expand_more
Yes. Prebuilt PDF report templates for NIS2, ISO 27001, GDPR/revDSG and FINMA. Complete audit trail, four-eyes principle, AES-256 encryption of sensitive configuration data and GDPR right to erasure (Art. 17) as a built-in platform feature. Development, operations and support exclusively from Switzerland.
Is there a local AI analyst?expand_more
Yes. IRONATE UEBA optionally offers an AI assistant that runs entirely on your own hardware, without any cloud dependency. Alert triage, threat summarization and recommended actions are generated in German, without your security data ever leaving the company network. Privacy by design, compliant with the Swiss Data Protection Act (FADP).