DETECT & INVESTIGATE

Shahbaz

SHAHBAZ

See unusual behavior before it becomes a threat.

Shahbaz continuously analyzes the behavior of users, accounts, assets and transactions to reveal anomalies in their real context and shorten the path from alert to evidence.

A closer look

Product brochure & demo

Download PDF

Product demo Shahbaz

The Story of Shahbaz

From a bird’s-eye view of data to the trail of a threat.

Knock at the door of meaning, and it will open to you.Beat the wings of thought, and you will become a royal falcon.

Rumi, Masnavi, Book I, Section 138 ↗

In Persian literature, the royal falcon evokes soaring ambition and a penetrating gaze. From above, it surveys the landscape, distinguishes the signs, and focuses on its quarry. For us, the beauty of this image lies in bringing breadth of vision together with precision of choice: seeing the whole, understanding movement, and finding what lies hidden in the details.

The name Shahbaz inspires this same perspective. Amid a stream of events, an unusual login, a change in behavior, or an unexpected connection can take on new meaning when seen alongside its history and context. Shahbaz brings these scattered signals together into a coherent picture of behavior and risk.

In Detect, this perspective guides behavior monitoring and anomaly detection. In Investigate, it focuses on a single entity, tracing its activity through timelines, connections, and evidence. For Shahbaz, threat hunting means uncovering the trail of a threat and guiding the analyst to the evidence that makes well-informed decisions and precise action possible.

See from above. Understand the signs. Track the threat.Banner motif: an artistic interpretation of the golden eagle emblem ↗

Detection and behavior analytics

Shahbaz at a glance

Shahbaz transforms scattered behavioral and security data into a unified view of entities, risks and evidence.
01

What is Shahbaz?

Shahbaz is a behavior analytics and anomaly detection system. It analyzes events associated with users, accounts, assets, devices and transactions together to reveal behavioral changes, rising risk and related evidence earlier.

02

When is it a good fit?

When event volumes are high, alerts lack context or investigating an entity requires manually collecting evidence from multiple sources.

03

Practical scenarios

Shahbaz Detect

For ongoing behavior monitoring, anomaly detection and alert prioritization.

Explore the analysis workflow
04

Designed for

  • Banks and financial institutions
  • Telecommunications operators and companies
  • Critical infrastructure
  • Government and public organizations
  • Holding companies and large organizations
  • SOCs and security teams
  • Any organization with high log volumes

Shahbaz is not limited to an industry. It suits any organization with connectable data, a meaningful number of users or important assets and a real detection or investigation need.

Analysis workflow

From scattered events to actionable signals

Shahbaz Detect

Explore each step
1 / 4

Data ingestion and correlation

Related events are collected from connectable sources and unified around entities.

Output of this stageEvents associated with an entity
What should you ask during evaluation?

Which sources and identifiers are available to link events to an entity?

This guide explains the product’s approach. Agree on an evaluation scope with Faraconesh to see how it works with your organization’s data.

Key capabilities

The insight analysts need to decide

Intelligent behavior analytics

Understand normal patterns and identify meaningful changes in user and entity behavior.

Anomaly detection and risk scoring

Combine related indicators to identify and prioritize cases requiring investigation.

Activity timeline

Reconstruct event sequences and observe changes linked to an entity over time.

Evidence search

Quickly find relationships, events and data associated with a person, account or asset.

Alert prioritization

Reduce attention to noise and guide analysts toward more important, actionable cases.

Shahbaz editions

Two paths, one analytical core

Shahbaz offers Detect and Investigate paths according to your starting point and required output.
Compare Shahbaz editions
Comparison criterionShahbaz DetectShahbaz Investigate
Main challengeDetect unusual behavior and hidden riskLack of a unified view for investigating an entity across the organization
Starting pointLive event and behavior streamsA specific person, account, IP, device or case
Key outputPrioritized alerts with context and risk scoresAn analytical entity case with a timeline and related evidence
Required dataConnectable logs, events, accounts, access or transactionsEntity identifiers and relevant historical data
Organizational usersSOCs, CERTs, security operations and incident response teams, information security managers and infrastructure monitoring teamsCorporate protection, physical and information security, HR, inspection, risk management, executives and decision makers
Selected edition
Shahbaz Detect
Main challenge
Detect unusual behavior and hidden risk
Starting point
Live event and behavior streams
Key output
Prioritized alerts with context and risk scores
Required data
Connectable logs, events, accounts, access or transactions
Organizational users
SOCs, CERTs, security operations and incident response teams, information security managers and infrastructure monitoring teams

Integration and deployment

Ready for integration and deployment

Shahbaz starts by gradually connecting your existing organizational data. The initial scope can be limited and manageable, then expanded after evaluating data quality and analytical results.

Connectable data

Application, network and service logs; endpoints; accounts and access; firewalls and VPN servers; security events and transactions.

Deployment within your organization

Adapted to your security requirements, data confidentiality and infrastructure architecture.

Phased rollout

Start with a defined scenario, user group or data source and expand gradually.

Starting prerequisites

Sample data, entity identifiers, a historical time range and a clear definition of the expected output.

For a more focused discussion

What do you have ready?

Check the items you have defined to see what still needs preparing for the introductory meeting.

Introductory meeting preparation

0 of 4 items ready

Still to be defined

  • Starting use case
  • Sample data from a connectable source
  • Identifiers and historical period
  • Expected output

Before you start

Frequently asked questions

Automatic playback · Paused

Detect starts with event streams to identify unusual behavior and prioritize alerts. Investigate starts with a specific person, account, IP address, device or case, bringing together the associated evidence and timeline.

Choose the right path

Not sure which Shahbaz edition is right for you?

Answer a few short questions about your challenge, available data and expected output to identify the right Detect or Investigate path.
Start a quick assessment Talk to the Faraconesh team