Find the Threats You Don't Know to Look For
Unsupervised Anomaly Detection Service helps to identify unknown, emerging, and hidden security threats across massive cybersecurity datasets.
Based on the Temporal Data Grid, UADS analyzes the shape, relationships, frequency shifts, and temporal behavior of your security data to surface high-value anomalies without relying on predefined rules, labels, signatures, or known threat patterns.
Request UADS BriefingThreat detection today is focused on the known, leaving a critical visibility gap in the face of machine-speed evolution.
The modern security landscape is saturated with threats that have not yet been recognized by traditional repositories.
Most detection stacks rely on known indicators, yet AI has drastically accelerated the rate at which zero-day vulnerabilities are identified and weaponized.
New threats, such as newly disclosed zero-days, are quickly exploited before rules can be written.
This creates a dangerous lag between the emergence of a novel attack path and the ability of indicator-based models to respond.
This exposure forces enterprises to confront the reality of the unknown.
Without a shift toward unknown anomaly awareness, organizations remain vulnerable to machine-speed evolution in attack strategies.
Unsupervised Anomaly Detection Overview
Unsupervised anomaly detection means finding threats without first telling the system what a threat looks like. Rule-based and signature-based tools can only detect behavior that someone has already described, which leaves a visibility gap for novel, slow-moving or insider activity. UADS takes the opposite approach: it learns what is normal for each user, device, application and network service directly from the organization’s own telemetry in the Temporal Data Grid, then surfaces combinations of behavior that deviate from that baseline across entities and time. Each anomaly is scored and explained in plain language, so an analyst sees a named, prioritized finding rather than a raw statistical alert, and the analyst’s verdict feeds back into the platform so the same pattern is not re-investigated from scratch. No signatures, training labels or detection rules are required, and the service runs on the same AI-ready data that powers the rest of the Cognitive Data Platform.
Knowledge Grid's Unsupervised Anomaly Detection Service is focused on the unknown unknowns.
UADS operates as an AI-native detection layer that moves beyond the limitations of static rules. By deploying unsupervised machine learning models across rich temporal security data, the service establishes a baseline of normal behavior unique to your environment without requiring prior knowledge of attack patterns or historical labels.
The core of the solution lies in its ability to surface behavioral anomalies at scale. Rather than searching for a needle in a haystack of known signatures, UADS analyzes complex relationships and shifts in data flow to identify novel attack paths and zero-day execution before they are classified by traditional security stacks.
Known knowns
Described, seen before
Known unknowns
Suspected, hunted by hand
Unknown knowns
In the data, never surfaced
Unknown unknowns
No rule, no label, no example
NO RULES · NO LABELS · NO TRAINING DATA REQUIRED
What Unsupervised Anomaly Detection Catches
Six classes of behavior that rules, signatures, and predefined searches often miss.
Volumetric
Anomaly
DEFINITION
An abnormal increase or decrease in the volume of activity compared to what is normally observed.
EXAMPLE
A workstation suddenly generates 10x more DNS queries than its normal baseline.
Zero-Day
Anomaly
DEFINITION
Detection of previously unseen or unknown threats that do not match any known signatures or rules.
EXAMPLE
A novel malware process is executed on an endpoint for the first time.
Reverse
Anomaly
DEFINITION
A deviation in the expected direction of an activity or behavior.
EXAMPLE
Data is sent from an internal server to a rare external IP instead of the expected inbound connection.
Diversity
Anomaly
DEFINITION
An unusually high variety of different entities, behaviors, or patterns in an activity.
EXAMPLE
A user account accesses a large number of different applications it has never used before.
Distinctive
Anomaly
DEFINITION
An activity that is statistically rare or stands out significantly from all other observed behavior.
EXAMPLE
A login from an unusual location at an odd hour that is rare compared to all other logins.
Dimensional
Anomaly
DEFINITION
An anomaly that exists in the combination of multiple attributes or in a unique multi-dimensional pattern.
EXAMPLE
A combination of uncommon process, parent process, user, and network destination that has never been seen together.
UAD Processing Flow
1. DATA SOURCES
High volume. High velocity. All your telemetry.
2. PARALLEL DETECTION ENGINES
Two complementary approaches. Complete coverage.
2A. EXISTING DETECTION
Your current investment
Detects known threats
What you already know to look for
2B. KNOWLEDGE GRID UADS
Learns normal behavior. No rules. No training data.
Detects unknown threats
What no one knows to look for
3. INTEGRATION & ENRICHMENT
Contextualize. Prioritize. Enrich.
SIEM / XDR
AI-ready anomaly output
4. AUTONOMOUS SECURITY
Actionable insights. Faster response.
SOC ANALYSTS
Enriched, prioritized alerts
THREAT HUNTING
Hidden and novel patterns
SOAR & SERVICE MGMT
Automated triage and workflow
CUSTOMER REPORTING
Demonstrable coverage
RISK & COMPLIANCE
Stronger posture, audit defensibility
The result is a smarter anomaly analysis layer that surfaces unknown, hidden, and emerging threats from the data you already collect.
UAD bridges the gap between known-indicator security and emerging behavioral threats.
Emerging Threat Detection
Identify new attack techniques as they emerge, before they are documented or assigned signatures.
Zero-Day Coverage
Detect novel exploit paths and zero-day style vulnerabilities that bypass rule-based models.
Eliminate Blind Spots
Connect behavioral anomalies across tool silos to eliminate the gaps between SIEM, EDR, and NDR.
High-Quality Signals
Reduce investigation time with high-fidelity, contextual anomaly signals optimized for technical teams.
Unsupervised Anomaly Detection Service
Our Unsupervised Anomaly Detection Service is designed to uncover the threats, behaviors, and operational changes that traditional rule-based tools typically miss. We focus on the Unknown Unknowns.
By analyzing large volumes of structured and unstructured data without requiring predefined signatures or labeled training sets, our service identifies meaningful deviations, rare patterns, and emerging activity hidden within complex environments. The result is a more adaptive, scalable approach to detection that helps organizations surface high-value anomalies earlier, reduce noise, and strengthen security operations.
Core Features
- Signatureless detection for unknown and emerging threats
- Behavior-based analysis across structured and unstructured data
- Temporal anomaly discovery that reveals change over time
- High-signal prioritization to reduce noise and speed investigation
Service Plan Comparison
Essential
Entry level affordability for getting started with essential capabilities.
Premium
Advanced capabilities with improved features to optimize detection capabilities with expanded models.
Unsupervised Anomaly Detection Service — Plan Options
ESSENTIAL
Entry level affordability for getting started with essential capabilities.
PREMIUM
Advanced capabilities with improved features to optimize detection with expanded models.
| FEATURES | ESSENTIAL | PREMIUM |
|---|---|---|
| Unsupervised Anomaly Detection (UADS Core) | Included | Included |
| Real-time Data Processing | Included | Included |
| Automated Baseline Learning | Included | Included |
| Multi-Source Log Ingestion | Included | Included |
| Threat Scoring & Prioritization | Included | Included |
| AI-Driven Anomaly Insights | Included | Included |
| Alerting & Notifications | Included | Included |
| Case Management Integration | Not included | Included |
| MITRE ATT&CK Mapping | Not included | Included |
| Custom Detection Views & Dashboards | Not included | Included |
| Historical Search & Investigation | Not included | Included |
| API Access & Integrations | Not included | Included |
| Advanced Entity & Behavior Analytics | Not included | Included |
| Data Retention (Up to 1 Year) | Not included | Included |
| Priority Support & SLA | Not included | Included |
| Dedicated Customer Success Manager | Not included | Included |