A security feature that uses machine learning to analyze user actions and file access patterns over time to establish a baseline of normal behavior. It then identifies and flags unusual activity, such as a large number of files being renamed or deleted, which can be an early indicator of a ransomware attack, data exfiltration, or an insider threat. This capability is a key component of Panzura CloudFS hybrid cloud file platform.