Identifying, building and acting on insider threat cases. This will include discussion of criminal trends and investigative practices, as well as balancing data security and user privacy.Learning Outcomes:Learn about effective ML-based threat detection methods applied on network data at scale.Gain knowledge into various evasion techniques adopted by adversaries and how can ML help uncover and circumvent them.Understand the importance of combining various ML techniques such as anomaly detection, clustering, graph analysis to detect new attacks and extract useful intelligence.Understand the types of "actionable intelligence" that ML can help us derive from large network data to minimise critical response time in prioritising and mitigating attacks.Learn best practices to upgrade technical intelligence with manual and automated ML methods useful to both defenders and Law enforcement for takedowns.