Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. technique: T1657 ✕
Download CSV Show ATT&CK heatmapPossible Insider Threat Activity Low Identity Threat Module 1 variation
A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- 3 Hours
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Financial Theft (T1657)Required data: AzureAD Audit Log Microsoft Graph Logs Office 365 Audit Okta Palo Alto Networks Global Protect Third-Party VPNs XDR Agent XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An insider threat might use their access to organizational resources for personal gain.Investigative actions: Check how long the user has been part of the organization. Check if the user is about to leave the company. Verify that the user is not part of a department that performs such activity as part of daily operations.Variations
Indicate Insider Threat Activity
Medium overridden
A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain. overridden