What is Shahbaz?
Shahbaz is a behavior analytics and anomaly detection system. It analyzes events associated with users, accounts, assets, devices and transactions together to reveal behavioral changes, rising risk and related evidence earlier.
DETECT & INVESTIGATE

Shahbaz continuously analyzes the behavior of users, accounts, assets and transactions to reveal anomalies in their real context and shorten the path from alert to evidence.
A closer look
The Story of Shahbaz
Knock at the door of meaning, and it will open to you.Beat the wings of thought, and you will become a royal falcon.
Rumi, Masnavi, Book I, Section 138 ↗
In Persian literature, the royal falcon evokes soaring ambition and a penetrating gaze. From above, it surveys the landscape, distinguishes the signs, and focuses on its quarry. For us, the beauty of this image lies in bringing breadth of vision together with precision of choice: seeing the whole, understanding movement, and finding what lies hidden in the details.
The name Shahbaz inspires this same perspective. Amid a stream of events, an unusual login, a change in behavior, or an unexpected connection can take on new meaning when seen alongside its history and context. Shahbaz brings these scattered signals together into a coherent picture of behavior and risk.
In Detect, this perspective guides behavior monitoring and anomaly detection. In Investigate, it focuses on a single entity, tracing its activity through timelines, connections, and evidence. For Shahbaz, threat hunting means uncovering the trail of a threat and guiding the analyst to the evidence that makes well-informed decisions and precise action possible.
See from above. Understand the signs. Track the threat.Banner motif: an artistic interpretation of the golden eagle emblem ↗Detection and behavior analytics
Shahbaz is a behavior analytics and anomaly detection system. It analyzes events associated with users, accounts, assets, devices and transactions together to reveal behavioral changes, rising risk and related evidence earlier.
When event volumes are high, alerts lack context or investigating an entity requires manually collecting evidence from multiple sources.
For ongoing behavior monitoring, anomaly detection and alert prioritization.
Explore the analysis workflowShahbaz is not limited to an industry. It suits any organization with connectable data, a meaningful number of users or important assets and a real detection or investigation need.
Analysis workflow
Shahbaz Detect
Explore each stepRelated events are collected from connectable sources and unified around entities.
Which sources and identifiers are available to link events to an entity?
Each user, account or asset develops a normal behavior profile within its own context.
What historical data is available to establish normal behavior in your organization?
Meaningful changes are identified and prioritized for investigation according to context and risk.
How does the analyst examine an alert’s context and the reason for its priority?
Evidence, relationships and timelines are available in a coherent view for analysis and decisions.
Can an investigation finding be traced back to related events and evidence?
This guide explains the product’s approach. Agree on an evaluation scope with Faraconesh to see how it works with your organization’s data.
Key capabilities
Understand normal patterns and identify meaningful changes in user and entity behavior.
Combine related indicators to identify and prioritize cases requiring investigation.
Reconstruct event sequences and observe changes linked to an entity over time.
Quickly find relationships, events and data associated with a person, account or asset.
Reduce attention to noise and guide analysts toward more important, actionable cases.
Shahbaz editions
| Comparison criterion | Shahbaz Detect | Shahbaz Investigate |
|---|---|---|
| Main challenge | Detect unusual behavior and hidden risk | Lack of a unified view for investigating an entity across the organization |
| Starting point | Live event and behavior streams | A specific person, account, IP, device or case |
| Key output | Prioritized alerts with context and risk scores | An analytical entity case with a timeline and related evidence |
| Required data | Connectable logs, events, accounts, access or transactions | Entity identifiers and relevant historical data |
| Organizational users | SOCs, CERTs, security operations and incident response teams, information security managers and infrastructure monitoring teams | Corporate protection, physical and information security, HR, inspection, risk management, executives and decision makers |
Integration and deployment
Application, network and service logs; endpoints; accounts and access; firewalls and VPN servers; security events and transactions.
Adapted to your security requirements, data confidentiality and infrastructure architecture.
Start with a defined scenario, user group or data source and expand gradually.
Sample data, entity identifiers, a historical time range and a clear definition of the expected output.
For a more focused discussion
Check the items you have defined to see what still needs preparing for the introductory meeting.
Introductory meeting preparation
0 of 4 items readyBefore you start
Detect starts with event streams to identify unusual behavior and prioritize alerts. Investigate starts with a specific person, account, IP address, device or case, bringing together the associated evidence and timeline.
Choose the right path