Hey folks, been hearing some chatter in the SIEM circles about a potential detection gap in Exabeam for data exfiltration scenarios. Specifically, around the behavioral analytics engine missing certain low-and-slow data transfers or encrypted outbound flows that don't trip traditional threshold alerts.
I was setting up some custom detection rules in Datadog for a similar use case (monitoring S3 bucket access patterns) and it got me thinking. In Exabeam, if the baseline for a user's "normal" data transfer volume is built over a long period, couldn't a malicious actor gradually increase their exfil just under that radar? Or if the data is encrypted, does the content analysis piece have visibility?
For anyone running Exabeam in production, have you run into this? I'm curious about:
* How you've tuned your use cases for data exfiltration.
* Whether you lean more on Exabeam's own rules or integrate with, say, a network DLP for richer context.
* Any workarounds like custom threat models or external log enrichment you've found effective.
Here's a super simplified example of the kind of outlier detection logic I might apply elsewhere to catch gradual volume increases:
```sql
# Pseudocode for trend analysis
SELECT user, destination_ip, SUM(bytes_sent) OVER (PARTITION BY user ORDER BY day ROWS 7 PRECEDING) as rolling_7day_avg
FROM network_logs
WHERE day = CURRENT_DATE()
AND rolling_7day_avg > (historical_baseline_for_user * 1.5) -- 50% increase over personal baseline
```
Would love to see if the community has real-world experiences or screenshots of their Exabeam dashboards tackling this. Sometimes the vendor docs don't tell the whole story!
Dashboards or it didn't happen.
Your point about low-and-slow transfers bypassing a behavioral baseline is valid. This is a classic limitation of any UEBA system relying solely on statistical deviation. The actor doesn't need to stay "under" the radar; they can be the one setting it by slowly increasing the new normal over weeks.
For encrypted flows, most SIEMs, including Exabeam, operate on metadata - packet size, destination, frequency - not content. That's why integration is key. In a cloud context, I've seen teams pair the behavioral scores with external context from a cloud-native tool. For example, triggering an Exabeam threat model when an IAM user's API call volume to S3 `GetObject` spikes, sourced from a separate CloudTrail analytics rule. The SIEM provides the user risk timeline, but the specific, suspicious event is defined elsewhere.
Have you considered the cost of logging the necessary flow data for this detection? The network log volume, especially with full packet capture for deeper analysis, can become a significant line item. Sometimes the detection gap is as much a budgetary constraint as a technical one.
Less spend, more headroom.