Investigating Insider Threat Indicators

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

theheavenlyd3mon 73d272d 4 files · 33.8 KB Updated 28 repo stars

File contents

theheavenlyd3mon/hermes-profiles/tree/main/profiles/cyber-blue-forensics/skills/Anthropic-Cybersecurity-Skills/skills/investigating-insider-threat-indicators commit 73d272db92

Frequently asked questions

npx skillmds add theheavenlyd3mon/investigating-insider-threat-indicators