Analytics Low

Possible Insider Threat Activity

A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.

Module:
Identity Threat Detection (ITDR)
Licensed by:
Identity Threat Detection (ITDR)
Data source:
AzureAD Audit Log, Microsoft Graph Logs, Office 365 Audit, Okta, Palo Alto Networks Global Protect, Third-Party VPNs, XDR Agent, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Financial Theft (T1657)
Attacker's goals:

An insider threat might use their access to organizational resources for personal gain.

Investigative actions:

Check how long the user has been part of the organization. Check if the user is about to leave the company. Verify that the user is not part of a department that performs such activity as part of daily operations.

Test period:
3 Hours
Deduplication:
1 Day
1 variation:
  • Indicate Insider Threat Activity Medium (parent: Low)