Microsoft Sentinel UEBA (User and Entity Behavior Analytics) helps security defenders identify malicious AWS activity by analyzing CloudTrail logs against established baseline patterns of normal user, peer, and device behavior. The capability generates behavioral signals to distinguish legitimate cloud operations from potential attacker actions.