Analytics
Low
✕
Possible Insider Threat Activity
A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.
- Module:
- Identity Threat Detection (ITDR)
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Financial Theft (T1657)
Attacker's goals:
An insider threat might use their access to organizational resources for personal gain.
Investigative actions:
Check how long the user has been part of the organization. Check if the user is about to leave the company. Verify that the user is not part of a department that performs such activity as part of daily operations.
- Test period:
- 3 Hours
- Deduplication:
- 1 Day
1 variation:
- Indicate Insider Threat Activity Medium (parent: Low)