What problem does it solve?
Security teams struggle to spot malicious insiders because their activity often looks authorized, and network-only monitoring misses high-signal exfiltration channels like USB copies, printing, and personal cloud uploads.
Core Features & Use Cases
- Hypothesis-Driven Hunting: A seven-step workflow from hypothesis formulation through query execution, validation, and reporting.
- Behavioral Detection Coverage: Detects unusual data access, off-hours activity, mass downloads, privilege abuse, and resignation-correlated data theft mapped to MITRE ATT&CK techniques T1078, T1530, and T1567.
- Detection Gap Guidance: Documents blind spots such as low-and-slow staging, per-user off-hours baselines, and privileged scope creep, with tuning advice for false positives.
- Use Case: An analyst hunting for an employee staging files before resignation correlates Windows Security events 4663/6416, DLP alerts, and HR signals to confirm bulk reads to USB and personal cloud storage.
Quick Start
Hunt for insider threat indicators by correlating per-user file access, removable media, and cloud upload telemetry against HR signals such as recent resignations.