Finding the Best Starting Point for Insider Threats and Other Workplace Investigations

No ratings

Presented at TechnoSecurity&Digital 2020 by

More than half of data breaches reported by organizations are insider incidents — either through the inadvertent or the malicious misuse of data. As enterprises expand the use of cloud-based services like SharePoint, Box, Dropbox, and Office365, they need to have a defined process and appropriate detection/investigative technologies to stay secure. Join Trey Amick, Forensics Consultant at Magnet Forensics, for a look into the most common practices when conducting corporate investigations. Workplace investigations are rarely straightforward, as examiners, HR, legal and compliance professionals, you need to efficiently recover data to protect company assets. We’ll explore how to find the best starting point for investigations like insider threats, employee misconduct and IP theft. From there, we’ll highlight the benefits of an artifact first approach including: • Filesystem artifacts relevant to corporate investigations • Simplify and expedite memory analysis with Volatility • Prove intent by visualizing relationships between files and actions • Access employee cloud accounts with administrator credentials