performing-insider-threat-investigation

Featured

Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection.

AI & Automation 12,642 stars 1468 forks Updated today Apache-2.0

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Performing Insider Threat Investigation ## When to Use - DLP (Data Loss Prevention) alerts on large data transfers to personal cloud storage or USB devices - User behavior analytics (UBA) detects anomalous access patterns for a user account - HR reports a departing employee suspected of taking proprietary information - A privileged user is observed accessing systems outside their job function - Whistleblower or coworker report alleges policy violations or data theft **Do not use** for external attacker investigations where compromised credentials are used without insider collusion; use standard incident response procedures instead. ## Prerequisites - Legal counsel approval before initiating any monitoring or investigation of an employee - HR partnership with defined investigation procedures and employee privacy guidelines - DLP platform with content inspection and policy enforcement (Symantec DLP, Microsoft Purview, Digital Guardian) - User behavior analytics platform (Microsoft Sentinel UEBA, Exabeam, Securonix) - Forensic imaging capability for endpoint examination - Chain of custody procedures for evidence that may be used in legal proceedings - Clear authority and scope documentation approved by legal and HR ## Workflow ### Step 1: Receive and Validate the Allegation Document the initial report and validate before proceeding: - Record the source of the allegation (DLP alert, UBA detection, HR referral, manager report) - Confirm with legal counsel that the inves...

Details

Author
mukul975
Repository
mukul975/Anthropic-Cybersecurity-Skills
Created
3 months ago
Last Updated
today
Language
Python
License
Apache-2.0

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Featured

investigating-insider-threat-indicators

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

12,642 Updated today
mukul975
AI & Automation Featured

detecting-insider-threat-behaviors

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.

12,642 Updated today
mukul975
AI & Automation Solid

detecting-insider-data-exfiltration-via-dlp

Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating insider threats or building user behavior analytics for data loss prevention.

12,642 Updated today
mukul975
AI & Automation Listed

internal-investigation

Use when supporting an attorney-directed internal investigation to track evidentiary coverage, connect evidence to issues, and draft a privileged investigation memorandum and audience-specific summaries as draft work product for attorney review.

1 Updated 2 days ago
zgbrenner
AI & Automation Featured

detecting-insider-threat-with-ueba

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.

12,642 Updated today
mukul975