<< All versions
Skill v1.0.0
currentAutomated scan100/100anxious-phyllo879/anthropic-cybersecurity-skills/detecting-insider-data-exfiltration-via-dlp
──Details
PublishedSeptember 28, 2026 at 08:42 AM
Content Hashsha256:65b664a335c1f543...
Git SHA
──Files
Files (1 file, 2.4 KB)
SKILL.md2.4 KBactive
SKILL.md · 86 lines · 2.4 KB
name: detecting-insider-data-exfiltration-via-dlp description: 'Detects insider data exfiltration by analyzing DLP policy violations, file access patterns, upload volume anomalies, and off-hours activity in endpoint and cloud logs. Uses pandas for behavioral analytics and statistical baselines. Use when investigating insider threats or building user behavior analytics for data loss prevention.
' domain: cybersecurity subdomain: security-operations tags:
- insider-threat
- data-loss-prevention
- dlp
- exfiltration-detection
- ueba
- security-operations
version: '1.0' author: mahipal license: Apache-2.0 nist_csf:
- DE.CM-01
- RS.MA-01
- GV.OV-01
- DE.AE-02
mitre_attack:
- T1078
- T1190
- T1059
- T1048
- T1041
Detecting Insider Data Exfiltration via DLP
When to Use
- When investigating security incidents that require detecting insider data exfiltration via dlp
- When building detection rules or threat hunting queries for this domain
- When SOC analysts need structured procedures for this analysis type
- When validating security monitoring coverage for related attack techniques
Prerequisites
- Familiarity with security operations concepts and tools
- Access to a test or lab environment for safe execution
- Python 3.8+ with required dependencies installed
- Appropriate authorization for any testing activities
Instructions
Analyze endpoint activity logs, cloud storage access, and email DLP events to detect data exfiltration patterns using behavioral baselines and statistical anomaly detection.
python
import pandas as pddf = pd.read_csv("file_activity.csv", parse_dates=["timestamp"])# Baseline: average daily upload volume per userbaseline = df.groupby(["user", df["timestamp"].dt.date])["bytes_transferred"].sum()user_avg = baseline.groupby("user").mean()# Alert on users exceeding 3x their baselinetoday = df[df["timestamp"].dt.date == pd.Timestamp.today().date()]today_totals = today.groupby("user")["bytes_transferred"].sum()anomalies = today_totals[today_totals > user_avg * 3]
Key indicators:
- Upload volume exceeding 3x daily baseline
- Access to files outside normal scope
- Bulk downloads before resignation
- Off-hours file access patterns
- USB/external device usage spikes
Examples
python
# Detect off-hours activitydf["hour"] = df["timestamp"].dt.houroff_hours = df[(df["hour"] < 6) | (df["hour"] > 22)]suspicious = off_hours.groupby("user").size().sort_values(ascending=False)