Security Ops: User Behavior Analytics & Anomaly Detection
Large-scale telemetry -> behavioral baselines -> explainable anomaly signals for SOC workflows.
- Processed enterprise telemetry streams (directory, proxy, endpoint) at scale.
- Unsupervised detection to surface meaningful anomalies with controllable false positives.
- Analyst-in-the-loop iteration and methodology docs to keep the system auditable.