Synopsis
Activation Period |
14 Days |
Training Period |
30 Days |
Test Period |
3 Hours |
Deduplication Period |
1 Day |
Required Data |
|
Detection Modules |
Identity Threat Module |
Detector Tags |
|
ATT&CK Tactic |
|
ATT&CK Technique |
|
Severity |
Low |
Description
A user was observed performing suspicious activity that might indicate an attempt to use their access to organizational resources for personal gain.
Attacker's Goals
An insider threat might use their access to organizational resources for personal gain.
Investigative actions
- Check how long the user has been part of the organization.
- Check if the user is about to leave the company.
- Verify that the user is not part of a department that performs such activity as part of daily operations.