Netskope LogoNetskope Logo
  • Security Services
  • AI Services
  • Networking Services
  • Analytics Services
  • Integrations
  • getting-started.svgGetting Started
    • Support
    • Community
    • Netskope.com
    © 2026 All Rights Reserved. Netskope Inc.
    Home
    Real-time Protection
    Insider Threats & Advanced Compromise Policies

    Insider Threats & Advanced Compromise Policies

    Netskope Insider Threats & Advanced Compromise policies support multiple types of user activity detection, including rule-based and machine learning-based (ML Based) detection engines.

    To access the behavior analytics summaries, go to Policies > Insider Threats & Advanced Compromise. The default view displays all policies.

    There are two types of policies:

    • Rule-Based: There are nine default Rule-Based policies. In addition, you can create custom rule-based policies.
      • Bulk Delete
      • Bulk Download
      • Bulk Failed Log ins
      • Bulk Upload
      • Proximity
      • Rare Event
      • Risky Countries
      • Shared Credentials
      • Suspicious Data Movement
    • ML Based: There is one default ML Based policy:
      • Machine Learning Model

    Click the tabs to view the Rule-Based and ML Based Policies details.

    In this Topic
    • Insider Threats & Advanced Compromise Policies