For the complete documentation index, see llms.txt. This page is also available as Markdown.

Possible Insider Threat Activity

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

3 Hours

Deduplication Period

1 Day

Required Data

Requires all of the following: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect OR Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)

Detection Modules

Identity Threat Module

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Financial Theft (T1657)

Severity

Low

Description

A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.

Attacker's Goals

An insider threat might use their access to organizational resources for personal gain.

Investigative actions

  • Check how long the user has been part of the organization.

  • Check if the user is about to leave the company.

  • Verify that the user is not part of a department that performs such activity as part of daily operations.

Variations

Indicate Insider Threat Activity

Synopsis

Field
Value

ATT&CK Tactic

Impact (TA0040)

ATT&CK Technique

Financial Theft (T1657)

Severity

Medium

Description

A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.

Attacker's Goals

An insider threat might use their access to organizational resources for personal gain.

Investigative actions

  • Check how long the user has been part of the organization.

  • Check if the user is about to leave the company.

  • Verify that the user is not part of a department that performs such activity as part of daily operations.

Was this helpful?