HOME>PRODUCTS>ANOMALY DETECTION
UNSUPERVISED ANOMALY DETECTION

Find the Threats You Don't Know to Look For

Unsupervised Anomaly Detection Service helps to identify unknown, emerging, and hidden security threats across massive cybersecurity datasets.

Based on the Temporal Data Grid, UADS analyzes the shape, relationships, frequency shifts, and temporal behavior of your security data to surface high-value anomalies without relying on predefined rules, labels, signatures, or known threat patterns.

Request UADS Briefing
BEHAVIOR FIELD — LAST 24H NO RULES · NO LABELS
3 ANOMALIES SURFACED LEARNED BASELINE
Volumetric shift Zero-day pattern Distinctive behavior
THE CHALLENGE

Threat detection today is focused on the known, leaving a critical visibility gap in the face of machine-speed evolution.

The modern security landscape is saturated with threats that have not yet been recognized by traditional repositories.

Most detection stacks rely on known indicators, yet AI has drastically accelerated the rate at which zero-day vulnerabilities are identified and weaponized.

New threats, such as newly disclosed zero-days, are quickly exploited before rules can be written.

This creates a dangerous lag between the emergence of a novel attack path and the ability of indicator-based models to respond.

This exposure forces enterprises to confront the reality of the unknown.

Without a shift toward unknown anomaly awareness, organizations remain vulnerable to machine-speed evolution in attack strategies.

HOW IT WORKS

Unsupervised Anomaly Detection Overview

Unsupervised anomaly detection means finding threats without first telling the system what a threat looks like. Rule-based and signature-based tools can only detect behavior that someone has already described, which leaves a visibility gap for novel, slow-moving or insider activity. UADS takes the opposite approach: it learns what is normal for each user, device, application and network service directly from the organization’s own telemetry in the Temporal Data Grid, then surfaces combinations of behavior that deviate from that baseline across entities and time. Each anomaly is scored and explained in plain language, so an analyst sees a named, prioritized finding rather than a raw statistical alert, and the analyst’s verdict feeds back into the platform so the same pattern is not re-investigated from scratch. No signatures, training labels or detection rules are required, and the service runs on the same AI-ready data that powers the rest of the Cognitive Data Platform.

Knowledge Grid's Unsupervised Anomaly Detection Service is focused on the unknown unknowns.

UADS operates as an AI-native detection layer that moves beyond the limitations of static rules. By deploying unsupervised machine learning models across rich temporal security data, the service establishes a baseline of normal behavior unique to your environment without requiring prior knowledge of attack patterns or historical labels.

The core of the solution lies in its ability to surface behavioral anomalies at scale. Rather than searching for a needle in a haystack of known signatures, UADS analyzes complex relationships and shifts in data flow to identify novel attack paths and zero-day execution before they are classified by traditional security stacks.

Unknown unknowns Unknown knowns Known unknowns Known knowns Rules-based SIEM Stops at the described core Knowledge Grid Covers all four classes
THREAT CLASS RULES & SIGS KNOWLEDGE GRID

Known knowns

Described, seen before

Known unknowns

Suspected, hunted by hand

—

Unknown knowns

In the data, never surfaced

—

Unknown unknowns

No rule, no label, no example

—

NO RULES · NO LABELS · NO TRAINING DATA REQUIRED

What Unsupervised Anomaly Detection Catches

Six classes of behavior that rules, signatures, and predefined searches often miss.

1

Volumetric

Anomaly

DEFINITION

An abnormal increase or decrease in the volume of activity compared to what is normally observed.

EXAMPLE

A workstation suddenly generates 10x more DNS queries than its normal baseline.

2

Zero-Day

Anomaly

DEFINITION

Detection of previously unseen or unknown threats that do not match any known signatures or rules.

EXAMPLE

A novel malware process is executed on an endpoint for the first time.

3

Reverse

Anomaly

DEFINITION

A deviation in the expected direction of an activity or behavior.

EXAMPLE

Data is sent from an internal server to a rare external IP instead of the expected inbound connection.

4

Diversity

Anomaly

DEFINITION

An unusually high variety of different entities, behaviors, or patterns in an activity.

EXAMPLE

A user account accesses a large number of different applications it has never used before.

5

Distinctive

Anomaly

DEFINITION

An activity that is statistically rare or stands out significantly from all other observed behavior.

EXAMPLE

A login from an unusual location at an odd hour that is rare compared to all other logins.

6

Dimensional

Anomaly

DEFINITION

An anomaly that exists in the combination of multiple attributes or in a unique multi-dimensional pattern.

EXAMPLE

A combination of uncommon process, parent process, user, and network destination that has never been seen together.

UAD Processing Flow

1. DATA SOURCES

High volume. High velocity. All your telemetry.

Endpoints / EDR Network / Firewall Cloud / SaaS Identity / IAM Applications Databases IoT / OT / ICS Email / Collab Logs & Events

2. PARALLEL DETECTION ENGINES

Two complementary approaches. Complete coverage.

2A. EXISTING DETECTION

Your current investment

Threat Intel
Rules
Correlation
Behavioral

Detects known threats
What you already know to look for

2B. KNOWLEDGE GRID UADS

Learns normal behavior. No rules. No training data.

Volumetric
Reverse
Zero-Day
Diversity
Distinctive

Detects unknown threats
What no one knows to look for

3. INTEGRATION & ENRICHMENT

Contextualize. Prioritize. Enrich.

SIEM / XDR

Ingest & normalize Correlate & enrich Alerts & dashboards Case management

AI-ready anomaly output

High-signal patterns Significance scoring Entity context Behavioral baselines

4. AUTONOMOUS SECURITY

Actionable insights. Faster response.

SOC ANALYSTS

Enriched, prioritized alerts

THREAT HUNTING

Hidden and novel patterns

SOAR & SERVICE MGMT

Automated triage and workflow

CUSTOMER REPORTING

Demonstrable coverage

RISK & COMPLIANCE

Stronger posture, audit defensibility

The result is a smarter anomaly analysis layer that surfaces unknown, hidden, and emerging threats from the data you already collect.

KEY BENEFITS

UAD bridges the gap between known-indicator security and emerging behavioral threats.

Emerging Threat Detection

Identify new attack techniques as they emerge, before they are documented or assigned signatures.

Zero-Day Coverage

Detect novel exploit paths and zero-day style vulnerabilities that bypass rule-based models.

Eliminate Blind Spots

Connect behavioral anomalies across tool silos to eliminate the gaps between SIEM, EDR, and NDR.

High-Quality Signals

Reduce investigation time with high-fidelity, contextual anomaly signals optimized for technical teams.

Unsupervised Anomaly Detection Service

Our Unsupervised Anomaly Detection Service is designed to uncover the threats, behaviors, and operational changes that traditional rule-based tools typically miss. We focus on the Unknown Unknowns.

By analyzing large volumes of structured and unstructured data without requiring predefined signatures or labeled training sets, our service identifies meaningful deviations, rare patterns, and emerging activity hidden within complex environments. The result is a more adaptive, scalable approach to detection that helps organizations surface high-value anomalies earlier, reduce noise, and strengthen security operations.

Core Features

  • Signatureless detection for unknown and emerging threats
  • Behavior-based analysis across structured and unstructured data
  • Temporal anomaly discovery that reveals change over time
  • High-signal prioritization to reduce noise and speed investigation

Service Plan Comparison

Essential

Entry level affordability for getting started with essential capabilities.

Premium

Advanced capabilities with improved features to optimize detection capabilities with expanded models.

Unsupervised Anomaly Detection Service — Plan Options

ESSENTIAL

Entry level affordability for getting started with essential capabilities.

PREMIUM

Advanced capabilities with improved features to optimize detection with expanded models.

UADS feature comparison: which of the 16 features are included in the Essential plan and which in Premium.
FEATURES ESSENTIAL PREMIUM
Unsupervised Anomaly Detection (UADS Core) Included Included
Real-time Data Processing Included Included
Automated Baseline Learning Included Included
Multi-Source Log Ingestion Included Included
Threat Scoring & Prioritization Included Included
AI-Driven Anomaly Insights Included Included
Alerting & Notifications Included Included
Case Management Integration Not included Included
MITRE ATT&CK Mapping Not included Included
Custom Detection Views & Dashboards Not included Included
Historical Search & Investigation Not included Included
API Access & Integrations Not included Included
Advanced Entity & Behavior Analytics Not included Included
Data Retention (Up to 1 Year) Not included Included
Priority Support & SLA Not included Included
Dedicated Customer Success Manager Not included Included
Included in Essential Included in Premium —Not included

UADS is the missing layer for unknown threats — complete your detection strategy today.