tag

insider-threat

5 indexed skills · max 10 per page

skills (5)

performing-user-behavior-analytics

mukul975/Anthropic-Cybersecurity-Skills · performing-user-behavior-analytics

0

Performs User and Entity Behavior Analytics (UEBA) to detect anomalous user activities including impossible travel, unusual access patterns, privilege abuse, and insider threats using SIEM-based behavioral baselines and statistical analysis. Use when SOC teams need to identify compromised accounts or insider threats through deviation from established behavioral norms.

detecting-insider-threat-with-ueba

mukul975/Anthropic-Cybersecurity-Skills · detecting-insider-threat-with-ueba

0

Implement User and Entity Behavior Analytics using Elasticsearch/OpenSearch to build behavioral baselines, calculate anomaly scores, perform peer group analysis, and detect insider threat indicators such as data exfiltration, privilege abuse, and unauthorized access patterns.

performing-insider-threat-investigation

mukul975/Anthropic-Cybersecurity-Skills · performing-insider-threat-investigation

0

Investigates insider threat incidents involving employees, contractors, or trusted partners who misuse authorized access to steal data, sabotage systems, or violate security policies. Combines digital forensics, user behavior analytics, and HR/legal coordination to build an evidence-based case. Activates for requests involving insider threat investigation, employee data theft, privilege misuse, user behavior anomaly, or internal threat detection.

investigating-insider-threat-indicators

mukul975/Anthropic-Cybersecurity-Skills · investigating-insider-threat-indicators

0

Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.

detecting-insider-threat-behaviors

mukul975/Anthropic-Cybersecurity-Skills · detecting-insider-threat-behaviors

0

Detect insider threat behavioral indicators including unusual data access, off-hours activity, mass file downloads, privilege abuse, and resignation-correlated data theft.