Insider risk investigations often begin with actions that look completely unremarkable on their own. When someone compresses a folder, or starts a transfer utility, it doesn't necessarily indicate a problem.
The challenge is understanding what surrounds them: what happened before and after, what information was involved, whether the behavior is normal for that user, and what the available evidence actually establishes.
In a recent hunt for a global company, Nebulock's agents applied that approach using the customer’s existing endpoint and identity data. The company wasn't short on tooling or visibility: it ran a mature security program across endpoint, identity, cloud, and DLP. But Nebulock combined their telemetry with stored context and agentic reasoning to catch real-time data exfiltration and other malicious insider activity that their existing stack missed.
By applying the right tools to the data they already own, security teams can proactively minimize insider risk by quickly identifying malicious activity before it escalates.
Weak signals rarely trigger an alert on their own
Following restructuring at the company, the Nebulock team initiated a hunt across their system for potential insider risk activity. It started from a question: are there signs that sensitive information is being collected or moved in ways that warrant investigation?
Organizational change events are some of the most common conditions for insider threats to emerge. Someone compressing a folder or starting a transfer utility doesn't necessarily indicate a problem. It's a weak signal in isolation. But this period can turn routine file activity into something worth a second look.
The hunt ran across activity that's commonly flagged during these change events:
- File collection and archiving
- Writes to secondary storage
- Transfer and cloud-sync activity
- Potential credential exports
- Unusual tooling
Each type of activity could be written as a detection rule to trigger an alert. But it could easily flood a SIEM or EDR with alerts that the security team would have to triage, or require further tuning to make less noisy.
By treating each activity as a starting point, not a conclusion, a hunt is able to do what an alert can't: explore weak signals to determine whether they become meaningful together, instead of waiting for one event strong enough to trip a detection.
Context reveals the bigger picture
File collection or unusual tooling alone doesn't give analysts much evidence to make a determination. They need to collect user identity, endpoint activity, and other telemetry to infer intent and build a story. But collecting that data for every instance of suspicious activity requires time and resources that don't scale, especially during a corporate restructuring.
Take that same file collection or other unusual tooling in the hunt list. On its own, an analyst still has to ask: Has this user done this before? Is it normal for their role? Has anything like it already been looked at and cleared? Then they have to chase down all the telemetry on their own to make a decision. Nebulock's TRACE Graph can answer that because it's automatically building a picture of what's normal, what's already been investigated, and where past activity has deviated from a person's usual pattern, well before the restructuring taking place.
So when the file collection shows up, it doesn't land as a bare, unexplained event. The analyst has the context to easily determine that the user doesn't normally do this and should be looked at, or that it's within scope for their role and level of permissions and can be dismissed. Having this context at the moment of the event allows analysts to move quickly and spend their attention on the cases worth investigating.
Reconstructing weak signals to uncover malicious intent
Some of the most significant findings emerged when Nebulock connected activity across time and systems.
In one case, we reconstructed a sequence: a user collected and archived sensitive business data, staged the files, then took action consistent with preparing them for transfer through a communication channel. The telemetry couldn't confirm the files left the organization or where they went, so it was flagged for immediate follow-up.
We then surfaced a second, separate case tied to the same user: data from a controlled business system was archived inside a virtual environment and transferred to the user's physical device.
This behavior wasn't isolated to one person, either. Multiple users showed activity worth a closer look, including large-scale movement of business data to secondary storage and collection of potentially sensitive corporate and credential-related material.
On their own, an archive, a moved file, and an opened messaging app look ordinary. Evaluated against the user's identity and the timing, they didn't. By reconstructing the behavior around it, the security team understood which combinations of activity actually mattered, and had a clear path for deciding the next step.
Not every flag is red
An equally important goal for the company was determining when activity was legitimate. The context-driven hunt identified benign activity and downgraded these findings instead of flagging for further investigation:
- Transfer activity that matched internal operational downloads.
- Archive commands that were routine dev workflows.
- An employee preserving their own personal employment records.
Distinguishing legitimate from malicious activity has real consequences for the people involved. A useful investigation shouldn't just explain why something deserves escalation. It should also be able to explain why something doesn't. Because Nebulock validated legitimate activity, the company was able to save their resources for real threats instead of chasing down false alarms.
Confidence during high-stakes events
By proactively hunting for insider risk activity, the company strengthened their program by efficiently directing their resources for legitimate threats during a high-stress time.
With a single hunt, the company easily filtered out benign activity to focus on remediating active insider threats. Instead of triaging alerts, they received a short, validated list of findings for follow-up, explanations for activity that had been investigated and downgraded, and clearly defined gaps where additional evidence was needed. They now add users to their Watchlist and continuously hunt for insider threats.
Nebulock helps teams use the telemetry they already have to confidently identify insider threats. By starting with context-rich hunting, teams can move quickly to stop the threats before they escalate and follow up on escalated findings that matter most.
If your insider risk program could use a second look, reach out to our team for a quick assessment.