Anomaly Detection
Noun · Security & Infosec
Definitions
Anomaly Detection is a detection approach that flags events, users, or systems that deviate from a learned baseline of normal behavior. Security teams use it to enforce trust, reduce exposure, improve detection, or standardize secure operations in production environments. Its value depends on correct configuration, lifecycle management, and surrounding controls, because weak defaults, poor integration, or missing visibility can create gaps that attackers exploit.
In plain English: Anomaly Detection is a security concept or control that helps organizations protect systems, manage trust, and notice suspicious behavior before damage spreads.
Example: "After the review, the security team rolled out Anomaly Detection in the affected environment, documented the operating procedure, and verified through logs and test cases that the control reduced exposure without breaking normal administrative or user workflows."
Related Terms
- Attack Surface Management
- Behavioral Analysis
- Cloud Security Posture Management
- CSPM
- Cyber Deception
- Data Loss Prevention
- Deception Technology
- Decoy System
- Device Fingerprinting
- DLP
- DNS Sinkhole
- Dwell Time
- Fingerprinting
- HIDS
- Host-Based Intrusion Detection
- IDS
- Indicator of Attack
- Indicator of Compromise
- Intrusion Detection System
- Intrusion Prevention System
- IP Reputation
- Log Correlation
- MITRE ATT&CK
- Network Intrusion Detection
- NIDS
- Security Information and Event Management
- Snort
- User and Entity Behavior Analytics
- XDR
- YARA Rule
- Adversary Emulation
- Automated Threat Detection
- Behavioral Detection
- Continuous Monitoring
- Correlation Rule
- Database Activity Monitoring
- Detection Engineering
- Detection Logic
- Honeynet
- Honeytoken
- Incident Detection
- IOA
- Monitoring Rule
- Pattern Detection
- Predictive Security
- Real-Time Alerting
- Retro Hunt
- Role Mining