A 100x spike that looked exactly like LDAP enumeration reconnaissance.
The Autonomous Hunter flagged a 100x surge in LDAP queries from a GitLab EKS node — indistinguishable from LDAP enumeration — and traced it to a legitimate OU expansion within minutes.
Traditional SIEM rules would never flag this. There is no signature for "your OU grew by 780 users and triggered an identity sync." Behavioral anomaly detection catches statistical deviations that rule-based systems cannot see by design.
The Autonomous Hunter traced the surge to a specific OU expansion — 780 users added to a managed users OU between Feb 16-19 — correlated with a dev build push, and identified the GitLab EKS sync job as the trigger. All in minutes.
This time it was benign. Next time the same signature could be active LDAP enumeration reconnaissance. Either way, you know immediately — with full context. That is the difference between monitoring and actual detection.