Detects anomalous behavior by authenticated users that may indicate insider threats through behavioral analysis of access patterns, privileged actions, and data movement.