I like that it is very customizable, so you can set up rules to detect any possible threat or issue across your organization's network infrastructure assets/devices! It does not yet have integrations for other 3rd party applications (like Splunk) which are helpful when working in an enterprise environment where different silos of data exist within our org., but we're hoping this will be added soon as well since there isn't much competition currently in terms of user behavior analytics products out their either - just some basic rule-based detection capabilities without heavy customizations required from users such as us who don’t necessarily work daily at IT departments or companies managing networks all day long every single week.
We've been able to reduce false positives by using advanced filtering options to create more specific alerts about certain threats being detected (such as Ransomware).