Possible Insider Threat Activity
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
3 Hours
Deduplication Period
1 Day
Required Data
Requires all of the following: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect OR Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Threat Module
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Financial Theft (T1657)
Severity
Low
Description
A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.
Attacker's Goals
An insider threat might use their access to organizational resources for personal gain.
Investigative actions
Check how long the user has been part of the organization.
Check if the user is about to leave the company.
Verify that the user is not part of a department that performs such activity as part of daily operations.
Variations
Was this helpful?
