No.1016
Threat detection.
No.1018
as an example, these guys use it (and other AI/ML) to model what endpoint should be doing, so they can detect anomalies despite encryption preventing DPI:
https://observable.net/what-we-do/endpoint-modeling/not shilling, i didn't get the job lol