elastic / elastic/roadmap

Entity Analytics - Entity Historical Context Changes on Behavioral Baseline and Anomalies

Open
#157 0 comments 0 reactions 1 assignee Assigned to @paulewing View on GitHub
product-area:security
Dominant language
No language data
Stars
6
Forks
1
PR merge metrics
No merged PRs in 30d

Description

**Problem**
To investigate effectively, analysts need immediate context on why a specific entity behavior was flagged as anomalous.

Using a "New Country Login" anomaly for user "John Doe" as an example:

Required Context: The analyst must immediately see the baseline behavior (e.g., "Baseline Country: USA") directly compared against the anomalous event (e.g., "Anomalous Login: Brazil").
Without this readily available comparative data, the analyst is forced to manually hunt for the user's behavioral history, which delays investigation and increases the mean time to resolution (MTTR).

**Value proposition**
Enable security analysts to conduct faster and more accurate threat hunts by providing them with the complete historical context and relationship mapping for entity and behavioral changes.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.