Once Insider Threats & Advanced Compromise is enabled in your account, the recommended next step is to disable the Standard UEBA policies.
Machine Learning detections in Insider Threats & Advanced Compromise will automatically learn the baselines for different users and raise individual alerts if there is anomalous behavior. Therefore, best practice is to disable the Standard UEBA policies.
The table below provides examples of the Insider Threats & Advanced Compromise policies that will supersede the corresponding Standard UEBA policies.
| Standard UEBA Policy | Insider Threats & Advanced Compromise Equivalent Example | Improvements |
|---|---|---|
| Bulk Failed Login | A user-based spike in failed login attempts | Insider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. |
| Bulk Delete | A user-based spike in files deleted detected from real-time protection | Insider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. |
| Bulk Upload | A user-based spike in sensitive data uploaded to personal apps | Insider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. In addition, Advanced UEBA also takes into account the nature of the data being moved by looking at associated DLP policy violation alerts. |
| Bulk Download | A user-based spike in sensitive files downloaded | Insider Threats & Advanced Compromise will build a baseline and alert when there is a deviation as opposed to a statically configured threshold. In addition, Advanced UEBA also takes into account the nature of the data being moved by looking at associated DLP policy violation alerts. |
| Proximity | First access from an IP block for the organization | Insider Threats & Advanced Compromise identifies a compromised credential being used when authentication or an admin activity happening from a network that has never been used before. This is higher fidelity compared to using ‘impossible travel’ to find possibly malicious activity because it hones in on specific malicious activity. |
| Risky Countries | First access from an IP block for the organization | Insider Threats & Advanced Compromise identifies compromised credentials using a more precise and baseline-based policy that uses IP blocks as opposed to a static country list. |
| Suspicious Data Movement | Potential sensitive data movement | Insider Threats & Advanced Compromise will build a baseline as well as monitor a wider range of application and app instances with no pre-configuration. In addition, Advanced UEBA policies do not require labeling of instances by the customer. |
| Rare Event | The 16+ policies beginning with “First access” | Insider Threats & Advanced Compromise uses a more precise set of policies to identify compromised credentials and insiders while significantly reducing the false positives from rare events that aren’t indicative of an insider threat or compromise. |
| Shared Credentials | Numerous policies that cover scenarios for Compromised credentials and Insider Threats with higher fidelity of detection examples:
| Insider Threats & Advanced Compromise uses a more precise set of policies to identify compromised credentials and insiders while significantly reducing the false positives from credential sharing that aren’t indicative of an insider threat or compromise. |
Setting Up a Low UCI Threshold Alert
You should ensure that an alert is generated every time a UCI score drops below a threshold. A low UCI alert is a signal that there is a user whose activity warrants analyst review. To configure this:
-
Go to the Incidents > Insider Threats & Advanced Compromise.
-
click
for Global UCI Alert.
-
As a best practice, Netskope recommends setting the User Confidence Index Threshold to
651so Netskope can generate an alert whenever a user’s UCI threshold drops below the “good” range and into the “moderate” range.
Setting Up a Process to Regularly Review Low UCI Users
A low UCI alert should trigger an analyst investigation. This alert will contain the user and information on the Key Detection Scenario that describes the likely cause for this low confidence score. In the low UCI example alert below, daniel@company.com had a low UCI due to Compromised device - Malware.

The investigation begins by going to Incidents > Insider Threats & Advanced Compromise and clicking the user’s name. This page lists all users and their UCI scores in increasing order.

For the selected user, the page will display a timeline of their UCI score. Click the day that their UCI score dropped to see the individual anomalies contributing to the score. In this example, the list of anomalies indicates that daniel@company.com is likely infected with ransomware. Clicking each individual anomaly will show additional context and an event timeline.

If an anomaly or set of anomalies are not an indicator that the user has a compromised device, compromised account, or is acting as an insider threat, you can click Mark as Allowed to remove the impact on the UCI as shown below. Marking an anomaly as allowed will suppress this anomaly from recurring for the same user and the same feature for 45 days.


