Microsoft Sentinel
Cloud and workloads

Investigate Incidents with UEBA Data

In brief

The article received updated wording, formatting, metadata, image markup, and related-content organization. Its preview notice and descriptions of UEBA investigation steps were also edited for consistency.

What Defender admins need to know

No administrator action is required. Use the refreshed article when guiding UEBA investigations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

In the Defender portal, a UEBA Anomalies tag identifies users with anomalies, making it easier to prioritize investigations.

The Top UEBA anomalies section -section, which appears on the User side panel and the Overview tab of the User entity page -page, displays the user's top three anomalies from the last 30 days. Select the links at the bottom of the Top UEBA anomalies section to hunt for all of the user's anomalies and view the Sentinel events timeline.

:::image type="content" source="media/investigate-with-ueba/entity-behavior-analytics-user-investigations.png" alt-text="Screenshot that shows the overview tab of the User page for a user with UEBA anomalies in the last 30 days." lightbox="media/investigate-with-ueba/entity-behavior-analytics-user-investigations.png":::

:::image type="content" source="media/identify-threats-with-entity-behavior-analytics/entity-behavior-analytics-incident-investigations.png" alt-text="Screenshot that shows an incident graph, highlighting the Go hunt All user anomalies option, which allows analysts to quickly find all anomalies related to the user." lightbox="media/identify-threats-with-entity-behavior-analytics/entity-behavior-analytics-incident-investigations.png":::

For more information,information about investigating user anomalies and the user entity page, see Investigate incidents in the Microsoft Defender portal and User entity page in Microsoft Defender.

Run proactive, routine searches on entity data

Investigate an anomalous sign-in

For example, the following steps follow the investigation of a user who connected to a VPN that they'd never used before, whichbefore. This unfamiliar VPN connection is an anomalous activity.

  1. In the Sentinel Workbooks area, search for and open the User and Entity Behavior Analytics workbook.
  2. Search for a specific user name to investigate and select their name in the Top users to investigate table. |Note the UsersInsights data | Scroll further to the right in the anomaly row to view the user insight data, such as the account display name and the account object ID. Select the text to view the full data on the right. | |Note the Evidence data | Scroll further to the right in the anomaly row to view the evidence data for the anomaly. Select the text view the full data on the right, such as the following fields:

    - ActionUncommonlyPerformedByUser
    - UncommonHighVolumeOfActions
    - FirstTimeUserConnectedFromCountry
    - CountryUncommonlyConnectedFromAmongPeers
    - FirstTimeUserConnectedViaISP
    - ISPUncommonlyUsedAmongPeers
    - CountryUncommonlyConnectedFromInTenant
    - ISPUncommonlyUsedInTenant |

Use the data found in the User and Entity Behavior Analytics workbook to determine whether the user activity is suspicious and requires further action.

Use UEBA data to analyze false positives

Analyze a false positive

For example, for an Impossible travel incident, after confirming with the user that a VPN was used, navigate from the incident to the user entity page. Use the data displayed thereon the user entity page to determine whether the locations captured are included in the user's commonly known locations.

For example:

Screenshot of an incident's user entity page showing user details and commonly known locations. :::image type="content" source="media/ueba/open-entity-pages.png" alt-text="Screenshot of an incident's user entity page showing user details and commonly known locations." lightbox="media/ueba/open-entity-pages.png":::

The user entity page is also linked from the incident page and from the investigation graph.

After confirming the data on the user entity page for the specific user associated with the incident, go to the Microsoft Sentinel Hunting area to understand whether the user's peers usually connect from the same locations as well. If so, this knowledge would make an even stronger case for a false positive.

In the Hunting area, run the Anomalous Geo Location Logon query. For more information, see Hunt for threats with Microsoft Sentinel.

Embed IdentityInfo data in your analytics rules (Public Preview)

The IdentityInfo table synchronizes with your Microsoft Entra workspace to create a snapshot of your user profile data, such as user metadata, group information, and Microsoft Entra roles assigned to each user. For more information, see IdentityInfo table in the UEBA enrichments reference.

See more information onFor details about the following operators and functions used in the SecurityEvent and SigninLogs query examples, insee the following Kusto documentation:

  1. Select the administrative user entity in the map, and then select Insights on the right to find more details, such as the graph of sign-ins over time.

  2. Select Info on the right, and then select View full details to jump to the user entity page to drill down further.

    For example, note whether this is the user's first Potential Password spray incident, or watch the user's sign-in history to understand whether the failures were anomalous.

URL detonation (Public preview)

When there are URLs in the logs ingested into Microsoft Sentinel, those URLs are automatically detonated to help accelerate the triage process.

The Investigation graph includes a node for the detonated URL, as well as the following details:

  • DetonationVerdict.: The high-level, Boolean determination from detonation. For example, Bad means that the side was classified as hosting malware or phishing content.
  • DetonationFinalURL.: The final, observed landing page URL, after all redirects from the original URL.

For example:

If you don't see URLs in your logs, check that URL logging, also known as threat logging, is enabled for your secure web gateways, web proxies, firewalls, or legacy IDS/IPS.

You can also create custom logs to channel specific URLs of interest into Microsoft Sentinel for further investigation.

Next stepsRelated content

Learn more about UEBA, investigations, and hunting: