You are here:
Login Anomaly
An anomalous login refers to the detection of a potential attacker attempting to gain unauthorized access to a legitimate user's account. This threat detection event identifies login attempts that deviate significantly from a user's typical login behavior, such as unusual times of day, unfamiliar devices (endpoints), or unexpected locations. Detecting these anomalies early is critical as a successful login is often the first step in broader malicious activities like data exfiltration or the deployment of malware and phishing campaigns.

