π€ Insider Threat theater
Covers malicious, negligent and recruited insiders who abuse authorized access to exfiltrate data, sabotage systems or enable espionage. Combines behavioral, financial and technical signals to detect the threat that bypasses the perimeter entirely.
Live indicators
54.5K
in this theater
High severity
0
score β₯ 0.75 (top 60)
Actors tracked
3
documented
Mapped sources
0
in catalog
🏹 Threat Actors
📚 Priority sources & datasets
📜 Insider Threat Playbook
- Collect access anomalies, mass-download and USB/cloud-egress events alongside HR risk indicators and dark-web insider-recruitment ads.
- Correlate identity, endpoint DLP and badge/VPN logs to build per-user behavioral baselines and deviation timelines.
- Analyze exfiltration staging, off-hours access and privilege escalation against known insider-kill-chain patterns.
- Attribute intent by tying activity to financial stressors, foreign-contact HUMINT signals or ransomware-crew insider bounties.
- Disseminate case packages to legal, HR and counterintelligence under strict need-to-know handling.
- Trigger access revocation, forensic imaging and coordinated interview/containment while preserving chain of custody for prosecution.
⚡ AI Skills & Automation
Automate unattended via the cron pipeline (collect → ingest → resolve → enrich → score → alert).
🎯 Add to case
🧩 Advanced Capabilities
🔗 Cross-domain pivots
Workstation Β· Copilot Β· AI Skills Β· Automation Β· Playbooks Β· Lookups Β· Docs Β· Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron