Insider Threat Detection Pack
52 cross-platform detection rules for insider threat — covering data staging before departure, bulk SaaS export, CRM data theft, knowledge base access anomalies, and HR-correlated risk signals. Your perimeter is your own people.
Pack summary
- Detection rules
- 52
- Critical severity
- 14
- Platforms covered
- 12+
- HR integrations
- 4
What's included
52 rules across 5 threat categories covering the full insider threat lifecycle.
Bulk SaaS download, external sharing, email forwarding, personal cloud upload, CRM bulk export.
Elevated activity correlated with resignation, PIP, or termination dates from HR system.
After-hours multi-platform access, first-time IP or country login, high-value directory access.
Admin role grant during offboarding, service account interactive use, MFA device enrollment.
USB DLP alerts, print jobs for sensitive documents, endpoint mass file movement.
Detection rules (20 of 52 shown)
Showing 20 representative rules. All 52 rules activate with one click.
| Rule name | Severity |
|---|---|
| Mass SaaS Data Download — Volume Anomaly | Critical |
| Drive / SharePoint / OneDrive — Bulk External Share Before Resignation Date | Critical |
| Email Forwarding Rule Created — All Mail to External Address | Critical |
| Cloud Storage — Personal Storage Service Upload (Dropbox, Box, WeTransfer) | High |
| Git Repository Clone of All Organisation Repos | High |
| Snowflake / BigQuery — Mass Data Export by User in Offboarding | Critical |
| SaaS Account Accessed After Work Hours — Multiple Platforms | High |
| CRM Bulk Export — Contact or Opportunity Records | Critical |
| Consecutive Login from Different Countries — Same Day | High |
| USB or Removable Media — DLP Alert | High |
| Intellectual Property Repository — First Access | High |
| Privilege Escalation — Admin Access Granted Within 30 Days of Resignation | Critical |
| IT Service Account Used After Business Hours by Non-Automation | High |
| Personal Email Accessed via Corporate Browser — Data Staging | Medium |
| Confluence / Notion — Bulk Page Export | High |
| HR System — Resignation or PIP Status Detected — Elevated Monitoring | Low |
| Anomalous Print Job — Sensitive Document Classification | High |
| File Access Pattern — High-Value Directories Not Normally Accessed | High |
| Multi-Factor Authentication — Enrolment of New Device During Offboarding | High |
| Cloud Infrastructure — Snapshot of Production Database Created | High |
Prerequisites
- At least one cloud or SaaS audit log source connected (Google Workspace, M365, Salesforce, Snowflake, GitHub)
- HR system integration (Workday, BambooHR, HiBob, or Rippling) for resignation and offboarding correlation
- Identity provider (Okta, Entra ID) connected for cross-platform user identity correlation
- Network proxy or DLP integration recommended for personal cloud storage upload detection
Insider Threat Detection Pack: frequently asked questions
How does ManySignal correlate HR system data with security events?
ManySignal integrates with HR systems (Workday, BambooHR, HiBob, Rippling) via SCIM or direct API. Resignation dates, PIP status, and termination dates are stored as user context attributes. Detection rules can use these attributes as conditions — for example, triggering only when a user downloading bulk data has an active resignation in the HR system.
Does this pack cover both malicious insiders and accidental data loss?
Yes. The pack includes rules for both intentional data exfiltration (bulk CRM export correlated with resignation date) and accidental data loss (personal cloud storage upload, unintended external share). Severity is calibrated accordingly — accidental patterns generate High alerts, while corroborated intent patterns generate Critical.
Can ManySignal detect data staging on personal devices?
ManySignal detects the data transfer events — SaaS downloads, cloud uploads, email attachments — but not what happens on the receiving device. For full visibility into personal device activity, endpoint DLP integration (Microsoft Purview, Forcepoint, Digital Guardian) is required and supported by this pack.
How does the pack handle false positives from legitimate data access?
Insider threat detections use a combination of volume thresholds (relative to the user's own baseline, not a fixed number), temporal correlation (activity coinciding with HR events), and access novelty (resources the user has not accessed before). This reduces false positives from heavy legitimate users while surfacing genuinely anomalous patterns.
Does this pack meet UEBA (User and Entity Behavior Analytics) requirements?
Yes. The insider threat pack provides UEBA-style detection through per-user baseline modelling, cross-platform activity correlation, and risk scoring. ManySignal maintains rolling 90-day behavioural baselines per user and surfaces deviations that exceed configurable thresholds. This satisfies UEBA requirements in frameworks like NIST SP 800-207 and common compliance programmes.
Detect insider threat before data leaves your organisation
52 cross-platform insider threat rules with HR system correlation — covering the full lifecycle from resignation date to bulk data export.