VYPR
researchPublished Sep 14, 2026· 1 source

Palo Alto Networks Unit 42 Unveils Behavioral Clustering for Cloud Identity Security

Unit 42 introduces a novel behavioral clustering model to map cloud identities to functional roles, enhancing threat detection by analyzing activity patterns in audit logs.

Palo Alto Networks' Unit 42 has developed an innovative behavioral clustering model designed to tackle the growing complexity of managing and securing identities within expanding cloud environments. As organizations increasingly rely on human, machine, and autonomous agent identities, accurately understanding their functional roles has become a critical security challenge. The new model analyzes activity patterns extracted from cloud audit logs, enabling continuous threat detection and providing deeper visibility into cloud operations.

The core of Unit 42's approach lies in its unsupervised machine learning algorithms, specifically Uniform Manifold Approximation and Projection (UMAP) and Hierarchical Density-Based Spatial Clustering of Applications with Noise (HDBSCAN). These algorithms are used to construct a reliable behavioral map, automatically categorizing a vast collection of cloud identities into distinct, clustered groups based on their executed operations. This method moves beyond traditional identity and access management (IAM) policies and naming conventions, which often fail to reveal an identity's true behavior due to masquerading techniques employed by attackers or simple misconfigurations.

In a comprehensive study, Unit 42 examined the behavior of over 40,000 identities across 125 cloud environments over a two-month period. This analysis allowed them to map these identities to common functional roles such as administrators, backup services, security tooling, and development and operations (DevOps) teams. The research highlights that an identity's permissions (what it *can* do) are distinct from its actual behavior (what it *does*), and it is the latter that provides richer context for threat detection.

A practical demonstration of the model's utility is provided through an in-depth analysis of the largest cluster identified: administrator console users in Amazon Web Services (AWS). By visualizing each identity as a data point on a behavioral map, where its invoked operations determine its coordinates, security teams can better differentiate between normal operational activity and potential malicious actions. For instance, an identity that frequently enumerates resources might be a legitimate security tool, or it could be an attacker probing the environment.

Furthermore, the model's findings can be translated into actionable security measures without requiring continuous, resource-intensive machine learning pipelines. Unit 42 demonstrates how lightweight heuristic logic can be extracted directly from the behavioral clustering map and implemented using standard SQL queries. This allows organizations to classify functional identity roles at scale, ensuring continuous operational visibility and enabling automated threat detection mechanisms.

While the research specifically focused on AWS CloudTrail data, Unit 42 emphasizes that the methodology is adaptable and can be extended to audit logs from other cloud providers, Software as a Service (SaaS) platforms, Kubernetes, and various other environments. This broad applicability makes the behavioral clustering model a versatile tool for enhancing cloud security posture across diverse infrastructures.

Palo Alto Networks offers several products and services that complement this research, including Cortex Cloud, Cortex XDR and XSIAM, and Idira Privileged Access Management (PAM) and Identity Governance and Administration (IGA). Additionally, their Unit 42 Cloud Security Assessment service can help organizations identify misconfigurations and security gaps in their cloud infrastructure.

Synthesized by Vypr AI