investigating-insider-threat-indicators

Featured

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Investigating Insider Threat Indicators ## When to Use Use this skill when: - HR refers a departing employee for monitoring during their notice period - DLP alerts indicate bulk data downloads or transfers to personal storage - UEBA detects anomalous access patterns deviating significantly from peer baselines - Management reports concerns about an employee accessing sensitive data outside their role **Do not use** without proper legal authorization — insider threat investigations must be coordinated with HR, Legal, and Privacy teams before monitoring begins. ## Prerequisites - Legal authorization and HR referral documenting investigation justification - SIEM with DLP, endpoint, email, proxy, and authentication log sources - Data Loss Prevention (DLP) system (Microsoft Purview, Symantec, Forcepoint) with policy alerts - Endpoint monitoring capability (EDR with USB/removable media logging) - HR data feed providing employment status, notice dates, and access entitlements - Chain of custody procedures for evidence preservation ## Workflow ### Step 1: Establish Investigation Scope and Legal Authorization Before any monitoring, ensure proper authorization: ``` INSIDER THREAT INVESTIGATION AUTHORIZATION ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ Case ID: IT-2024-0089 Subject: [Employee Name] — [Department] Authorized By: [CISO / General Counsel] Referral Source: HR — Employee submitted resignation, 2-week notice Justification: Employee has acc...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

performing-insider-threat-investigation

Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection.

12,642 Updated today
mukul975
AI & Automation Featured

detecting-insider-threat-behaviors

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.

12,642 Updated today
mukul975
AI & Automation Solid

detecting-insider-data-exfiltration-via-dlp

Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating insider threats or building user behavior analytics for data loss prevention.

12,642 Updated today
mukul975
AI & Automation Featured

detecting-insider-threat-with-ueba

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.

12,642 Updated today
mukul975
AI & Automation Solid

hr-investigation

Support workplace investigation processes with documentation and methodology guidance

1,034 Updated today
a5c-ai