M ManySignal
Detection Pack Cross-Platform

Insider Threat Detection Pack

52 cross-platform detection rules for insider threat — covering data staging before departure, bulk SaaS export, CRM data theft, knowledge base access anomalies, and HR-correlated risk signals. Your perimeter is your own people.

Pack summary

Detection rules
52
Critical severity
14
Platforms covered
12+
HR integrations
4

What's included

52 rules across 5 threat categories covering the full insider threat lifecycle.

Data Staging & Exfiltration 20 rules

Bulk SaaS download, external sharing, email forwarding, personal cloud upload, CRM bulk export.

HR-Correlated Risk 12 rules

Elevated activity correlated with resignation, PIP, or termination dates from HR system.

Access Anomalies 10 rules

After-hours multi-platform access, first-time IP or country login, high-value directory access.

Privilege Abuse 6 rules

Admin role grant during offboarding, service account interactive use, MFA device enrollment.

Physical & Endpoint 4 rules

USB DLP alerts, print jobs for sensitive documents, endpoint mass file movement.

Detection rules (20 of 52 shown)

Showing 20 representative rules. All 52 rules activate with one click.

Rule name Severity
Mass SaaS Data Download — Volume Anomaly Critical
Drive / SharePoint / OneDrive — Bulk External Share Before Resignation Date Critical
Email Forwarding Rule Created — All Mail to External Address Critical
Cloud Storage — Personal Storage Service Upload (Dropbox, Box, WeTransfer) High
Git Repository Clone of All Organisation Repos High
Snowflake / BigQuery — Mass Data Export by User in Offboarding Critical
SaaS Account Accessed After Work Hours — Multiple Platforms High
CRM Bulk Export — Contact or Opportunity Records Critical
Consecutive Login from Different Countries — Same Day High
USB or Removable Media — DLP Alert High
Intellectual Property Repository — First Access High
Privilege Escalation — Admin Access Granted Within 30 Days of Resignation Critical
IT Service Account Used After Business Hours by Non-Automation High
Personal Email Accessed via Corporate Browser — Data Staging Medium
Confluence / Notion — Bulk Page Export High
HR System — Resignation or PIP Status Detected — Elevated Monitoring Low
Anomalous Print Job — Sensitive Document Classification High
File Access Pattern — High-Value Directories Not Normally Accessed High
Multi-Factor Authentication — Enrolment of New Device During Offboarding High
Cloud Infrastructure — Snapshot of Production Database Created High

Prerequisites

  • At least one cloud or SaaS audit log source connected (Google Workspace, M365, Salesforce, Snowflake, GitHub)
  • HR system integration (Workday, BambooHR, HiBob, or Rippling) for resignation and offboarding correlation
  • Identity provider (Okta, Entra ID) connected for cross-platform user identity correlation
  • Network proxy or DLP integration recommended for personal cloud storage upload detection

Insider Threat Detection Pack: frequently asked questions

How does ManySignal correlate HR system data with security events?

ManySignal integrates with HR systems (Workday, BambooHR, HiBob, Rippling) via SCIM or direct API. Resignation dates, PIP status, and termination dates are stored as user context attributes. Detection rules can use these attributes as conditions — for example, triggering only when a user downloading bulk data has an active resignation in the HR system.

Does this pack cover both malicious insiders and accidental data loss?

Yes. The pack includes rules for both intentional data exfiltration (bulk CRM export correlated with resignation date) and accidental data loss (personal cloud storage upload, unintended external share). Severity is calibrated accordingly — accidental patterns generate High alerts, while corroborated intent patterns generate Critical.

Can ManySignal detect data staging on personal devices?

ManySignal detects the data transfer events — SaaS downloads, cloud uploads, email attachments — but not what happens on the receiving device. For full visibility into personal device activity, endpoint DLP integration (Microsoft Purview, Forcepoint, Digital Guardian) is required and supported by this pack.

How does the pack handle false positives from legitimate data access?

Insider threat detections use a combination of volume thresholds (relative to the user's own baseline, not a fixed number), temporal correlation (activity coinciding with HR events), and access novelty (resources the user has not accessed before). This reduces false positives from heavy legitimate users while surfacing genuinely anomalous patterns.

Does this pack meet UEBA (User and Entity Behavior Analytics) requirements?

Yes. The insider threat pack provides UEBA-style detection through per-user baseline modelling, cross-platform activity correlation, and risk scoring. ManySignal maintains rolling 90-day behavioural baselines per user and surfaces deviations that exceed configurable thresholds. This satisfies UEBA requirements in frameworks like NIST SP 800-207 and common compliance programmes.

Detect insider threat before data leaves your organisation

52 cross-platform insider threat rules with HR system correlation — covering the full lifecycle from resignation date to bulk data export.