Fired but not gone: two layers of protection against an insider

General News

Summary

This article explains how to detect insider threats in Active Directory using a layered security approach. It walks through indicators such as privileged account sprawl, stale accounts, weak password controls, non-expiring passwords, and suspicious service accounts. It also compares Active Directory audit data with user behavior analytics to spot unusual activity tied to departures or exfiltration attempts. The piece positions AI-driven monitoring and read-only audit tooling as ways to reduce false positives and improve SOC response to insider risk.

Classifications

industries
No industries detected
applications
Accounting and Taxes

AskAI Classifications

Labels
Cybersecurity Software as a Service (SaaS) Data Loss Prevention

Linked Companies

DTEX Systems
$10M to $25M
Cisco
$1B+
Microsoft
$1B+
Telegram Messenger
$1M to $5M