What problem does it solve?
SOC teams receiving insider threat referrals often lack a structured, legally sound methodology to investigate data exfiltration, unauthorized access, and anomalous employee behavior across fragmented log sources.
Core Features & Use Cases
- Exfiltration Detection: Splunk SPL queries detect bulk SharePoint/OneDrive downloads, USB device usage, external email attachments, and cloud storage uploads.
- Behavioral Anomaly Analysis: Identifies after-hours activity spikes, unauthorized application access, and deviations from role-based peer baselines.
- HR and Physical Correlation: Aligns digital activity with resignation timelines, badge access logs, and notice periods to build investigation timelines.
- Evidence Preservation: Python-based chain-of-custody logging with SHA-256 hashing for legally defensible evidence packages.
- Use Case: When HR refers a departing employee with access to trade secrets, use this Skill to build a 90-day activity timeline, detect low-and-slow exfiltration under DLP thresholds, and produce an investigation report for Legal review.
Quick Start
Investigate user jsmith for insider threat indicators during their two-week notice period using our SIEM, DLP, and badge access logs.