Skip to main content

User behavior risks

The User Behavior Risks page displays all the risks caused by the reckless or unintentional actions of active users, or lack of measures taken to properly secure their working sessions while in your network. It provides detailed info of the level of severity, number of vulnerable users, risk status and type.

Note

See User Behavior Risk Data Collection for more details on how we process user data.

era_user_behavior_risks_937535_en.png
  1. The Smart views panel toggle button. This feature allows you to customize, save, and switch between different loadouts of the User behaviour risks page.

    era_user_behavior_risks_smart_views937535_en.png

    The panel has the following sections:

    • Search views - Use this search field to filter out the views displayed in the sections below, by name.

    • Saved - This section displays a list of all your saved views that have not been marked as favorites.

    • Favorites - All views marked as favorites are displayed under this section.

    • Defaults - This section displays the views that are available by default:

      • All human behavior behavior risks

      • High severity

      • Detected

      • Ignored

      • CIS compliant

      • Watchlist

    For any view in the Saved or Favorites category, you can click ellipses.PNG to Rename or Delete the view.

  2. The User behavior risk actions. This section contains the buttons to all the available actions you can take on the risks displayed on the page:

    • State - Change the state of the selected risks. The following options are available:

      • Ignore risks

      • Restore ignored risks

    • Watchlist - Add or removed the selected risks from your watchlist. The following options are available:

      • Add to watchlist

      • Remove from watchlist

    • Scan - Perform a scan to check for new risks or updates on known risks.

  3. The Filters section. You can use these options to customize the risks that are displayed in the below grid.

    The following filters are currently available:

    Filtering option

    Details

    Human risk

    Use the searchable drop-down menu to filter the list of User behavior risks by name. Select the User behavior risks you want to display and click Apply.

    Only the selected User behavior risks are displayed.

    Risk score

    Select a risk score range between 1 and 100.

    Only User behavior risks with a risk score between these values are displayed.

    Mitigation type

    Use the searchable drop-down menu to filter the list of User behavior risk by mitigation type. Select the mitigation types you want and click Apply. Possible values:

    • Manual

    • Automatic

    Only User behavior risks where the types of mitigation you selected applies are displayed.

    Vulnerable users

    Use the searchable drop-down menu to filter the list of vulnerable users by name. Select the users you want and click Apply.

    Only User behavior risk that apply to the selected users are displayed.

    OS

    Use the searchable drop-down menu to filter the list of devices by operating system. Select the operating systems you want and click Apply. Possible values:

    • Unknown

    • IOS

    • Android

    • Windows

    • Linux

    • Solaris

    • Mac OS X

    • Container

    Only User behavior risks that affect the selected operating systems are displayed.

    Status

    Use the searchable drop-down menu to filter the list of User behavior risks by status. Select the statuses you want and click Apply. Possible values:

    • Compliant

    • Detected

    Only User behavior risks with the statuses you selected are displayed.

    State

    This column allows you to filter the list of indicators of risk by their status, Active or Ignored.

    Use the searchable drop-down menu to filter the list of devices by state. Select the states you want and click Apply. Possible values:

    • Active

    • Ignored

    Only User behavior risks with the states you selected are displayed.

    Compliance

    Select the Compliance Standard you want to display the Misconfigurations for.

    Only Misconfigurations resulted from checks based on rules belonging to the Compliance Standards you selected are displayed.

    In watchlist

    Use this filter to display User behavior risks based on them currently being included in a watchlist. Possible values:

    • Yes

    • No

  4. The View options menu. This section provides you with multiple functions for working with views:

    • Save - Save changes you make to a saved view.

    • Save as - Save a modified view under a different name.

    • Discard changes - Revert the saved view to its original state.

    • Add to favorites - Add the view to the Favorites category.

    • Show or hide filters - Hide or display the filters menu.

    • Open settings - Display the Settings panel.

      You can use this panel to customize what columns are displayed in the view and enable or disable the Compact view.

  5. The Human behavior risks grid. The grid displays all known User behavior risks in your company, based on your last scan.

    The information available for each User behavior risks displayed under the following columns:

    • Human risk - The name of the User behavior risk.

    • Risk score - The risk score of the User behavior risk.

    • Vulnerable users - Displays the number of users that the User behavior risk applies to, grouped by type (local, AD).

    • OS - The type of operating system that is affected by the User behavior risk.

    • Mitigation type - The type of mitigation that can be applied to this User behavior risk.

    • Status - The status of the User behavior risk.

    • State - The state of the User behavior risk.

    • Compliance - The compliance standard that was applied in the check that resulted in the detection of the Misconfiguration.

    • In watchlist - Indicates if the User behavior risks currently in the watchlist.

    Note

    More details regarding the information in each column are available type in the Filters section.

  6. Actions button - Displays all the actions you can take on each User behavior risk. Possible values:

    • Ignore risk

    • Add to watchlist