GTI - Insider Threat Alert Detected

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Triggers an incident when a GTI Relevance System Alert of type insider_threat is ingested. Insider Threat alerts indicate that GTI has identified intelligence suggesting malicious or negligent activity by individuals with legitimate access to your organisation - such as employee credential sales, internal data exposure, or rogue employee activity observed in underground sources. Each unique Alert ID is grouped into a single incident.

Attribute Value
Type Analytic Rule
Solution Google Threat Intelligence
ID e5f6a7b8-c9d0-1234-efab-345678901234
Severity High
Status Available
Kind Scheduled
Tactics PrivilegeEscalation, Exfiltration, CredentialAccess, Impact
Techniques T1068, T1078, T1567, T1552, T1485
Required Connectors GoogleThreatIntelligenceRelevanceSystemAlertsAPI
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
RelevanceSystemAlerts_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Google Threat Intelligence