High severityHARDEC6 steps · 5 phases
Insider Threat / Data Collection
Insider threat / authorized user data collection/exfiltration.
Information note
Informational note: In insider threat scenarios, data collection activity often remains covert for extended periods; detect abnormal bulk download behavior targeting SharePoint, OneDrive, and local network shares using DLP and UEBA tools (MITRE T1213, T1039). Low-volume techniques such as clipboard data and screen capture (T1115, T1113) may evade signature-based tools; prioritize behavioral baseline deviations and off-hours access anomalies.
1
Preparation
1 steps- Insider threat program
UEBA, DLP, least privilege, offboarding process, legal/HR coordination.
2
Detection & Analysis
1 steps- Validate anomalous behavior
Excessive data access/download, off-hours activity, USB/cloud upload, scope and intent.
3
Containment, Eradication & Recovery
2 steps- Restrict access (confidentially)
Narrow/suspend the suspect account's access, preserve evidence, conduct confidentially with HR/legal.
- Revoke privileges
Remove access/devices/accounts, freeze shared secrets, detect externally copied data.
4