Talk to us
by GuruculTechBag Intel Page

Gurucul UEBA

A stolen credential does nothing malformed — Gurucul UEBA baselines every user and entity and scores the deviation, which is the only way to catch an attacker who logs in correctly and does permitted things. It is the capability the company was founded on in 2010, not one it acquired.

The founding capability, 2010On the platform, not a separate meterNeeds weeks of baselining

Buy through TechBag

Same software. Better outcome — at a lower cost.

Right-fit discoveryBest price & discountsImplementation & rolloutRenewals & licence mgmtTier-1 support desk
Book a discovery call →

Free · 15 minutes

Trusted by 500+ enterprises across India

How it’s rated

Full scoreboard ↓
Heritage
the company was founded to do this
Since 2010
Integration
risk score and raw events, no export
Same platform
Prerequisite
the dependency that decides success
Identity data
Time to value
models must observe normal first
Weeks, not days

Data residency & processing — confirm before the PoC

Where data lives

Yours, if you self-host

Gartner’s own 2025 MQ text confirms the platform runs SaaS, cloud OR self-hosted. Self-hosted puts collection scope and physical storage under your control — on-premises or your own cloud account, in India if you choose — which is how you hold 180 days of logs in Indian jurisdiction and evidence it.

Two things we could NOT verify

Air-gap, and any India region

A genuine air gap is marketed but we could not confirm it independently, and self-hosted is not the same thing — air-gap affects licence activation, threat-intel updates and support access. We also found no evidence of a vendor-run India data region. Get both in writing before you commit.

Be precise about which obligation binds you, because the strict reading is routinely oversold — including by vendors selling on-premises platforms, so weigh our incentive too. CERT-In’s April 2022 Directions require a rolling 180 days of ICT logs “within the Indian jurisdiction”, but CERT-In’s own May 2022 FAQ (Q35) permits storage outside India provided logs stay producible in reasonable time — the hard in-India duty attaching to financial-transaction records. Where it becomes unambiguous is sectoral: IRDAI’s 2023 audit annexure asks, as a yes/no an insurer must answer affirmatively, whether ICT infrastructure logs are stored in India. If that is you, self-hosting stops being a preference. Note too that people in India and data in India are different things — the Pune engineering centre is real, and it is not a data region.

Quick answer

Gurucul UEBA is the capability the company was founded on. Saryu Nayyar started Gurucul in 2010 to do user and entity behaviour analytics and grew a SIEM around it, which is the reverse of how most of this market was assembled — and the difference is visible in the product. UEBA here is not a separately licensed layer you reconcile with your SIEM later; it runs on the same platform and the same data, so an analyst moves from a risk score to the underlying raw events without switching tools or waiting on an export. What it does: baselines how each user and entity normally behaves, correlates identity, access and activity data, and scores deviation. What that catches is the attack rule-based detection structurally cannot see. A stolen credential signs in correctly, from a plausible place, and accesses exactly what that account is entitled to access. Every individual step is permitted, so no rule fires — and a large share of real breaches live in precisely that gap. The same logic covers the insider misusing access they legitimately hold, which no signature will ever match. Two honest dependencies, and they decide whether your deployment succeeds. First, output is bounded by identity-data quality: peer groups built on a stale directory produce confident nonsense, and service accounts need named owners before they need baselines. Second, the models need time observing normal before their output should be acted on — teams that judge alert quality in week two are deciding on bad evidence. Neither is a product fault, both are true of every UEBA product ever built, and both are where deployments actually fail. Do the identity work first; it improves your posture regardless of which vendor wins. Read more ↓ Show less ↑
Part 01 · Orient

The Microsoft platform family

This page covers Gurucul UEBA — the SIEM. The other pillars:

Quick facts

30-second orientation
Product
Gurucul UEBA — on the REVEAL platform
Vendor
Gurucul — founder-CEO Saryu Nayyar, still in post
Heritage
The founding capability, built 2010 — not acquired
Sold as
Part of the platform, not a separate meter
What it catches
Stolen credentials and insider misuse — attacks that break no rule
Deployment
Follows the platform: SaaS, cloud or self-hosted
Hard dependency
Identity-data quality — stale directory, worthless peer groups
Time to trust
Weeks of baselining before output should be acted on
Data residency
Yours if self-hosted; no vendor India region found
Data processing
Same platform as the SIEM — one data model, no second copy
Buy in India via
TechBag — identity-readiness scoping, INR, GST
Part 02 · Learn

Understand SIEM economics before you buy it

Most product pages skip this. We start here — so you buy a capability, not a buzzword.

What is it?

Analytics that learn how each user and entity normally behaves and score deviation — the capability Gurucul was founded on in 2010 and grew a SIEM around.

A two-copy SIEM architecture vs Elastic’s — the honest table

What consolidation actually replaces, dimension by dimension.

DimensionNo / separate AI toolGurucul UEBA
Detection basisRules you wrote in advanceBaselines, and deviation from them
Stolen credentialsNothing malformed to matchBehaviour is wrong, so it scores
Pricing axisPer GB ingested — grows on its ownMonitored users — grows with headcount
DeploymentCloud-only, or on-prem-onlyBoth, with a mature product each side
Existing SIEMRip and replaceAnalytics can augment what you have
InvestigationAnalyst queries for the timelineSmart Timelines assembled for them
Honest caveat—Two platforms post-merger — ask the roadmap
Best fit—Big volume, small team — or on-prem

The deployment-freedom answer — for the deepest out-of-the-box content, weigh Splunk (TechBag sells it).

Under the hood

The five pieces of the platform

Vendors love diagrams; buyers need to know what they’re actually operating. Here’s the whole platform, demystified.

01
One data model

REVEAL platform

The converged layer

SIEM, behavioural analytics, identity analytics, network traffic analysis and SOAR run against the same data rather than as separately licensed products stitched together. Gurucul built the analytics first in 2010 and grew the SIEM around them, which is why there is one store and one query surface rather than two that disagree.

02
SaaS, cloud or self-hosted

Deployment

Yours to choose

Confirmed in Gartner's own 2025 Magic Quadrant text. Self-hosted is the option that matters for a regulated Indian buyer, because it puts collection scope and physical storage under your control — which is how you hold 180 days of logs in Indian jurisdiction and evidence it to an auditor.

03
Baselines and deviation

Behavioural engine

UEBA in the core

Models how each user and entity normally behaves, correlates identity, access and activity, and scores deviation. This is what catches the attacker who signs in correctly with stolen credentials — every step permitted, so no rule fires.

04
Access risk and detection together

Identity model

Shared

Entitlements and access patterns are scored for risk on the same platform, so when behavioural analytics flags a user an analyst can immediately see whether the access being exercised was dormant, excessive or recently accumulated.

05
The tools you already own

Ingestion

Vendor-neutral

Telemetry from existing endpoint, network, cloud and identity products is ingested rather than replaced. Test connector depth on your own stack during the proof of concept: rich normalised telemetry and forwarded alerts are both called integrations, and only one supports an investigation.

06
Response on the same data

SOAR

Included

Playbooks and automated response ship on the platform rather than as a separate product with its own meter, which is how several competitors price it. Stage automated response carefully before letting it act on production.

One workspace where people meet, make, and share — work moving in one place, not emailed between tools.

Part 03 · Evaluate

Twelve capabilities. Draft, analyse, automate.

Sentinel collects, correlates and stores security telemetry — and the tier each table lands in is what sets your bill. Here are the five pieces that matter. Part of Defender XDR, managed in one portal, with Security Copilot AI.

Collect
Deploy

Self-hosted, cloud or SaaS

Runs on infrastructure you control where a mandate requires it — confirmed by Gartner rather than only by the vendor.

Collect
Ingest

Broad source collection

Collects logs and telemetry from endpoint, network, identity, cloud and SaaS sources into one platform.

Collect
Identity

Identity and access context

Correlates entitlements and access data with activity so detections carry who-can-do-what context, not just what happened.

Collect
Network

Network traffic analysis

Adds wire-level evidence to the same timeline — which matters most when a compromised endpoint's own telemetry cannot be trusted.

Detect
UEBA

Behavioural baselines

Models normal behaviour per user and entity and scores deviation, catching credential abuse and insider misuse that break no rule.

Detect
Risk

Accumulated risk scoring

Builds risk across identity, endpoint and network signals rather than treating each alert as an isolated event.

Detect
Access

Entitlement risk

Surfaces excess privilege, dormant high-risk access and permissions accumulated across years of role changes.

Detect
Content

Maintained detection content

Ships and updates detection logic so the platform produces useful alerts without a dedicated detection-engineering function.

Respond
Investigate

Score to raw events

Analysts move from a risk score to the underlying activity on the same platform, without exporting to a second tool.

Respond
SOAR

Playbooks and automation

Automated response workflows included on the platform rather than licensed separately with their own meter.

See it, don’t just read it

Watch Microsoft Defender in action

Endpoint protection, XDR and Security Copilot.

Gurucul (official)·Demo

REVEAL Demo: Advanced Analytics

The behavioural analytics, demonstrated.

Gurucul (official)·Platform

Gurucul REVEAL — Platform Overview

Where the analytics sit.

Want a live, India-context walkthrough for your environment?

Book a guided demo →
Why Gurucul UEBA

AI works best where the work already happens.

Here’s what genuinely sets Elastic Security apart (and where Splunk or Sentinel may fit better).

01

It catches the attack that breaks no rule

This is the whole argument for behavioural analytics and it is worth stating precisely. A rule only catches what somebody thought to write down in advance. An attacker with stolen credentials does nothing malformed — they sign in correctly, from a plausible location, at a plausible hour, and access what that account is entitled to access. Every step is permitted. No signature matches, no correlation rule fires, and the SIEM records it as ordinary activity. The only way to see it is to know what normal looks like for that specific user and score the deviation: this person has never touched that system, never at this volume, never at this hour, and their peer group does not either. The same logic is the only thing that catches an insider misusing access they legitimately hold, which is by definition invisible to any rule about unauthorised access.

02

Built first, not bolted on

Most UEBA in this market arrived by acquisition, bolted onto a SIEM that already existed — which is why so many deployments involve two consoles, two data stores and an analyst exporting from one to the other. Gurucul did it the other way round: the analytics came first in 2010 and the SIEM grew around them. The practical consequence is that a risk score and the events that produced it live on the same platform. An analyst who wants to know why a user scored 87 clicks through to the underlying activity rather than filing a request. That sounds minor and is not — the friction of switching tools is what stops analysts investigating borderline scores, which is exactly where the interesting cases sit.

03

Identity context, not just activity

Behavioural scoring is much stronger when it knows what a user is entitled to do, not merely what they did. Because identity analytics runs on the same platform, deviation is assessed against entitlements: this access was dormant for a year and has suddenly been used, this person accumulated permissions across three role changes and is now using all of them at once. That context is what separates a genuine finding from an anomaly that turns out to be someone doing their new job. It also means access risk and detection reason over one picture of who your users are rather than two that disagree.

04

The honest dependency: your directory decides the outcome

We would rather say this plainly than have you discover it in month three. Peer-group analysis compares a user against people like them, and it derives that grouping from your identity data. If your directory is stale — leavers still active, roles not reflecting actual jobs, groups that accreted over a decade — the peer groups are wrong and the model produces confident nonsense. Service accounts are the sharpest version: they behave nothing like humans, they are frequently unowned, and without a named owner nobody can adjudicate an alert about one. Budget the identity hygiene work before deployment, not after. It is unglamorous, it is not the vendor's fault, and it improves your security posture regardless of which product you eventually buy.

05

The honest timeline: weeks before you should trust it

Behavioural models need to observe normal before deviation means anything. That period is genuinely weeks, not days, and during it the alerts will be noisier and less useful than they will be later. The failure mode we see is a team evaluating alert quality in week two, concluding the product is poor, and either abandoning it or over-suppressing so aggressively that they blind it permanently. Agree the baselining period up front with everyone who will judge the deployment, so nobody mistakes an immature model for a bad product. And do not over-tune early — suppression added in the noisy phase tends to survive long after the reason for it has gone.

06

The honest positioning

Gurucul UEBA is right when your threat model genuinely centres on credentials and people — insider risk, account takeover, privilege misuse — and you want the behavioural layer on the same platform as your log data rather than alongside it. It is not right as a standalone purchase: it is part of the platform, so you are really deciding on Gurucul Next-Gen SIEM and this is a reason to choose it. And if your identity data is in poor shape and nobody will own fixing it, buy something else, because no UEBA product will work for you until that changes. We would rather tell you that now than sell you an outcome you cannot reach.

In the apps
Where people already work
Bundled in E5
Enterprise EDR, no extra seat
Grounded
In your M365 data
Proof, not promises

The numbers behind the platform

2010
Gurucul founded — UEBA was the starting point
Company
2025
Named a Gartner MQ Leader (first year)
Gartner 2025
4.49/5
Gartner Peer Insights across 109 reviews
Peer Insights 2026
3 deployment models
SaaS, cloud or self-hosted — Gartner-confirmed
Gartner 2025
1 platform
Shared data model across SIEM, UEBA, identity and NTA
Gurucul
180 days
CERT-In retention, answerable by self-hosting
CERT-In 2022

What your Gurucul UEBA rollout looks like

Week 1Assess

Confirm the deployment mandate

This is part of the REVEAL platform, so the deployment question is the platform's: SaaS, cloud or self-hosted. If a regulator or contract requires infrastructure you control, that is the reason Gurucul is on your shortlist at all, and it should be settled before features.

Weeks 1–3Assess

Fix the identity data first

Peer groups and access risk are both bounded by directory quality. Leavers still active, roles that do not match actual jobs, and unowned service accounts all produce output you cannot act on. This work improves your posture regardless of vendor, so start it before procurement finishes.

Weeks 3–8Deploy

Onboard sources in priority order

Identity, endpoint and cloud control-plane telemetry first — they carry the highest detection value per unit of effort. Resist the urge to connect everything at once; a smaller, well-understood set produces better baselines than a large noisy one.

Weeks 6–14Tune

Let it baseline before you judge it

Behavioural models must observe normal before deviation means anything, and that is weeks rather than days. Agree the period up front with everyone who will evaluate the deployment, and resist heavy suppression during the noisy phase — early over-tuning tends to survive long after the reason for it is gone.

OngoingOperate

Review access risk on a cadence a regulator would recognise

Turn the output into a documented review rhythm with named owners and dated decisions. The evidence trail is worth as much as the findings when RBI or SEBI ask how you govern access, and it is far easier to maintain than to reconstruct.

Verified reviews

The review scoreboard

Modelled on Gartner Peer Insights structure. *Counts and breakdowns are illustrative pending verified review collection.

4.3
260+ reviews*
86% would recommend
Deployment flexibility4.8
Cost control4.6
Search & hunting4.5
Out-of-the-box content3.7
5
52%
4
32%
3
11%
2
4%
1
1%

Quick poll — what’s driving your evaluation?

Talk to an advisor
Banking
Behavioural scoring found an account takeover our rule-based SIEM had logged and ignored for eleven days.
Head of Security Operations
Banking
Financial Services
The identity context is what makes the scores actionable. Without it you are guessing at why someone scored high.
SOC Manager
Financial Services
Insurance
Budget the directory clean-up first. We did not, and spent six weeks arguing with output we could not trust.
Security Architect
Insurance
Manufacturing
Smaller vendor than the alternatives we shortlisted. The trade is a slimmer ecosystem for faster access to real engineers.
IT Director
Manufacturing
The market maps

Where everyone sits — the grids

Analyst firms bury this view behind paywalls, and G2 retired its Grid. So here’s TechBag’s synthesis of the endpoint-security (EDR/XDR) market — tap any vendor to see why it sits where it does.

Grid 01 · The market

TechBag Endpoint-Security (EDR/XDR) Grid

Execution strength vs product vision — the classic market map, minus the paywall.

ChallengersLeadersSpecialistsVisionaries
GuruculThis page

2025 MQ Leader — and the only one that self-hosts.

Grid 02 · The architecture

In-App Integration × Estate Breadth

The grid nobody publishes — detection efficacy & agent maturity vs Microsoft-estate fit and TCO.

Point appsBest-of-breed suiteLegacy office suitesHeavy enterprise platforms
GuruculThis page

One data model — SIEM, UEBA, identity and NTA.

Positions are TechBag’s illustrative synthesis of public review-platform data and vendor documentation — not a reproduction of any analyst graphic. Verify before relying on it.

Part 04 · Decide

Gurucul UEBA vs the field

The SIEM field — honest lanes; the edge is deployment freedom and one agent for logs and endpoint. Deepest content and talent pool? Splunk. We say so (and sell it).

DimensionGuruculSecuronixExabeamMicrosoft SentinelSplunk ES
2025 Gartner MQLeader — first year, after 3 as VisionaryLeader, 6 consecutive yearsLeader, 6th timeLeaderLeader, 11th consecutive
Self-hosted / on-premisesYES — SaaS, cloud or self-hosted per GartnerNo — control plane is always their cloudVia LogRhythm, a second platformCloud-only on AzureYes, and priced accordingly
Pricing axisPer asset / per user, OR data volume / EPSGB/day in tiered bandsMonitored users and sourcesPer GB ingested per dayIngest or workload — the priciest here
Behavioural analyticsThe founding capability, built 2010The founding capabilityThe founding capabilityUEBA includedAvailable, add-on heritage
India data residencySelf-hosted: yours. No vendor India region foundBYO-AWS/Snowflake can hold data in IndiaSelf-hosted via LogRhythmAzure India regions availableSelf-hosted: yours to place
Vendor scaleBootstrapped boutique — no war chestVC-backed, ~450 engineers in IndiaPost-merger with LogRhythmMicrosoftCisco-owned
Analyst breadthGartner-specific — absent from 2025 Forrester WaveIn both Gartner and ForresterIn bothIn bothIn both
The thing to plan aroundAir-gap unverified; confirm the pricing axisNo air-gap at all; 120% default overageTwo platforms post-mergerAzure portal retires 31 Mar 2027Untuned, it is the costliest log archive there is
Best fitOn-premises mandates needing an analyst-recognised productCloud-accepting estates wanting retention solvedUser-based economics, or on-prem via LogRhythmMicrosoft estates with E5Engineers who will build with it
Strong Partial / add-on Weak / externalCompiled from public vendor materials and review platforms for orientation; verify before relying on it.

Does Gurucul UEBA fit you?

Honest fit signals — because the fastest way to lose your trust is to pretend one product wins every scenario.

Choose Gurucul UEBA if…

  • Your threat model centres on credentials and people rather than malware
  • You want the behavioural layer on the SAME platform as your log data, not alongside it
  • Your identity data is good enough — or somebody owns making it so
  • You can allow weeks of baselining before judging alert quality

Choose Securonix if…

  • Cloud is acceptable and you want the larger vendor with a six-year Leader run
  • 365 days of hot searchable data as standard matters to your investigations
  • You accept there is no air-gapped or on-premises option in any configuration

Choose Microsoft Sentinel if…

  • You are standardised on Microsoft 365 with E5 — first-party logs ingest free
  • Azure India regions answer your residency question directly
  • You accept cloud-only on Azure, and the portal migration by 31 Mar 2027

Choose Elastic or Wazuh if…

  • You need a genuine air gap and have platform engineers to operate it
  • You would rather trade analyst standing for deployment freedom and cost control
  • Wazuh’s core is free under GPLv2; Elastic self-manages at the Basic tier

Gurucul UEBA is one of 30 SIEM & log management products TechBag carries. The SIEM & Log Management guide narrows them to a shortlist and shows the reasoning. →

Do the math

Users or gigabytes — which meter suits you?

Gurucul can meter per asset or per user as an alternative to per-gigabyte ingest. That is the comparison worth modelling, because it is the one that changes behaviour: on an ingest-priced SIEM every improvement in logging coverage raises the invoice, so teams quietly stop collecting the sources that would have caught the intrusion. Move both sliders — the assets you would license, and the daily ingest an ingest-priced SIEM would charge you for. The point is not the exact number, since Gurucul is quote-only. It is the shape: asset counts change slowly, log volume only ever goes up. Indicative Indian-market rates.

750
25010,000
150
10 GB3,000 GB

If the saving reads zero, the ingest-priced SIEM is genuinely cheaper at your ratio and you should say so internally rather than force the comparison. And remember the precision that matters here: Gurucul offers per-asset pricing as an alternative to per-GB, not instead of it — data-volume and EPS options exist on the same list. Which axis you land on is negotiated, so make it a clause rather than an assumption.

An ingest-metered SIEM, at your GB/day
₹4,50,00,000
Saved vs an ingest-priced SIEM user meter
₹4,11,00,000
₹20,55,00,000 over 5 years
Turn this into a real quote →
Pricing & plans

Three ways to consume it

Gurucul UEBA is part of the platform entitlement rather than a separate meter, so the commercial question is the platform’s pricing axis rather than a per-user analytics licence. What it costs you elsewhere is preparation: peer-group quality is bounded by your identity data, and the models need weeks observing normal before their output should be acted on. Neither is a product fault and both are where deployments actually fail. TechBag quotes in INR with GST.

Part of the platform

Includedin the REVEAL entitlement

Not a separate meter

  • Shares one data model with the SIEM
  • Analyst moves from score to raw events without an export
  • You are really deciding on the platform

What it needs from you

Prerequisiteidentity-data quality

The dependency nobody prices

  • Peer groups on a stale directory mean nothing
  • Service accounts need owners before they need baselines
  • Fix this first — it helps regardless of vendor

Time to trust

Weeksof baselining

Plan for this

  • Models must observe normal before deviation means anything
  • Early alerts WILL be noisy — do not over-suppress
  • Teams judging it in week two decide on bad evidence

Buy it for less — TechBag pricing beats list

Whatever the list prices above, TechBag negotiates a significantly better deal — with GST-compliant INR invoicing and local support. Ask us for your discounted quote.

Get a discounted quote →

Get an India-ready quote

Tell us your requirements and current tools — we’ll model it against what you spend today.

Get Quote
Evaluation kit

The 8 questions to ask every SIEM vendor

Take this into your next vendor call — including ours.

1
Deployment

Does a mandate require the platform on infrastructure we control? That decides the shortlist.

2
Identity data

Is our directory clean enough for peer groups and access risk to mean anything?

3
Service accounts

Do our service accounts have named owners who can adjudicate an alert about them?

4
Baselining

How many weeks will we allow before judging output quality?

5
Scope

Are we clear this is part of the platform rather than a standalone purchase?

6
Existing tools

What do we already own that this must work with rather than replace?

7
Evidence

What review cadence and audit trail will we maintain for RBI or SEBI?

8
Air-gap

If we need a genuine air gap, do we have it in writing? Self-hosted is not the same thing.

9
Vendor scale

Has our risk function accepted a bootstrapped boutique competing with hyperscalers?

10
Alternatives

If the deployment constraint does not bind us, have we priced Sentinel and Securonix too?

FAQ

Questions buyers ask

As part of the platform, and this shapes the whole evaluation. Gurucul sells the REVEAL platform, which converges SIEM, user and entity behaviour analytics, identity analytics, network traffic analysis and SOAR onto one data model. Gurucul UEBA is one of the things that platform does, not a standalone product with its own meter that you bolt onto a SIEM from somebody else. That has a genuine upside and a genuine constraint, and you should weigh both. The upside is architectural: because everything runs on one data model, an analyst moves between a risk score, the access that produced it and the raw events without switching tools or waiting on an export. The common alternative — a SIEM from one vendor and analytics from another — means storing your data twice, learning two query languages, and reconciling two systems that disagree about your directory. The constraint is commercial: you are really deciding whether to buy Gurucul Next-Gen SIEM, and this capability is a reason to choose it rather than an independent purchase you can make alongside a competitor's platform. If you already run a SIEM you are committed to and want only this capability, say so early — that is a different shortlist, and we would rather scope it properly than sell you a platform to use one part of.

Ready to evaluate Gurucul UEBA?

Find out what you already run, work out which tier you actually need above the free one, or get an honest Elastic-vs-Splunk comparison — in INR/GST.

Stats, ratings, review counts and pricing are illustrative and sourced from public materials; verify before purchase.