Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Behavior Analytics
    Insider Threats & Advanced Compromise
    Quick Start

    Quick Start

    Once Insider Threats & Advanced Compromise is enabled in your account, the recommended next step is to disable the Standard UEBA policies.

    Machine Learning detections in Insider Threats & Advanced Compromise will automatically learn the baselines for different users and raise individual alerts if there is anomalous behavior. Therefore, best practice is to disable the Standard UEBA policies.

    The table below provides examples of the Insider Threats & Advanced Compromise policies that will supersede the corresponding Standard UEBA policies.

    Standard UEBA PolicyInsider Threats & Advanced Compromise Equivalent ExampleImprovements
    Bulk Failed LoginA user-based spike in failed login attemptsInsider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold.
    Bulk DeleteA user-based spike in files deleted detected from real-time protectionInsider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold.
    Bulk UploadA user-based spike in sensitive data uploaded to personal appsInsider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. In addition, Advanced UEBA also takes into account the nature of the data being moved by looking at associated DLP policy violation alerts.
    Bulk DownloadA user-based spike in sensitive files downloadedInsider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. In addition, Advanced UEBA also takes into account the nature of the data being moved by looking at associated DLP policy violation alerts.
    ProximityFirst access from an IP block for the organizationInsider Threats & Advanced Compromise identifies a compromised credential being used when authentication or an admin activity happening from a network that has never been used before. This is higher fidelity compared to using ‘impossible travel’ to find possibly malicious activity because it hones in on specific malicious activity.
    Risky CountriesFirst access from an IP block for the organizationInsider Threats & Advanced Compromise identifies compromised credentials using a more precise and baseline-based policy that uses IP blocks as opposed to a static country list.
    Suspicious Data MovementPotential sensitive data movementInsider Threats & Advanced Compromise will build a baseline as well as monitor a wider range of application and app instances with no pre-configuration. In addition, Advanced UEBA policies do not require labeling of instances by the customer.
    Rare EventThe 16+ policies beginning with “First access”Insider Threats & Advanced Compromise uses a more precise set of policies to identify compromised credentials and insiders while significantly reducing the false positives from rare events that aren’t indicative of an insider threat or compromise.
    Shared CredentialsNumerous policies that cover scenarios for Compromised credentials and Insider Threats with higher fidelity of detection examples:
    • Potential compromised credential being used from a non-Netskope IP address
    • Access from an unusual country for the organization
    • Access from an unusual country for the user
    • Activity detected outside user’s regular working hours
    • AWS IAM activity without MFA from a non-Netskope IP address
    • Compromised credential found in a data breach
    Insider Threats & Advanced Compromise uses a more precise set of policies to identify compromised credentials and insiders while significantly reducing the false positives from credential sharing that aren’t indicative of an insider threat or compromise.

    Setting Up a Low UCI Threshold Alert

    You should ensure that an alert is generated every time a UCI score drops below a threshold. A low UCI alert is a signal that there is a user whose activity warrants analyst review. To configure this:

    1. Go to the Incidents > Insider Threats & Advanced Compromise.

    2. click for Global UCI Alert.

    3. As a best practice, Netskope recommends setting the User Confidence Index Threshold to 651 so Netskope can generate an alert whenever a user’s UCI threshold drops below the “good” range and into the “moderate” range.

    Setting Up a Process to Regularly Review Low UCI Users

    A low UCI alert should trigger an analyst investigation. This alert will contain the user and information on the Key Detection Scenario that describes the likely cause for this low confidence score. In the low UCI example alert below, daniel@company.com had a low UCI due to Compromised device - Malware.

    The investigation begins by going to Incidents > Insider Threats & Advanced Compromise and clicking the user’s name. This page lists all users and their UCI scores in increasing order.

    For the selected user, the page will display a timeline of their UCI score. Click the day that their UCI score dropped to see the individual anomalies contributing to the score. In this example, the list of anomalies indicates that daniel@company.com is likely infected with ransomware. Clicking each individual anomaly will show additional context and an event timeline.

    If an anomaly or set of anomalies are not an indicator that the user has a compromised device, compromised account, or is acting as an insider threat, you can click Mark as Allowed to remove the impact on the UCI as shown below. Marking an anomaly as allowed will suppress this anomaly from recurring for the same user and the same feature for 45 days. 

    In this Topic
    • Quick Start