Icon-Check@3x
CPE Cyber Attack Lab #2

Detecting & Investigating Insider Threats

Mon, October 26 | 3:00 pm EDT

Watch a disgruntled software engineer go rogue! We'll show you how the attack is performed and what the corresponding alerts look like in Varonis.

In a devious attempt to steal sensitive financial info, our insider finds a list of service accounts with admin privileges, performs a Kerberoasting attack to hijack a backup service's credentials, and sends a ZIP full of sensitive info to a personal Gmail account.

+1 CPE

Register Now

About this webinar

See how Varonis uncovers indicators of compromise at every turn.

  • An insider was paid to exfiltrate sensitive organizational data
  • To cover his tracks, he takes control of a service account with elevated privileges
  • Using the service account, he scans company file shares for documents with certain keywords
  • Copies matching documents to his PC
  • Creates an encrypted ZIP file
  • He uses the service account to exfiltrate the ZIP file as an attachment to a personal Gmail account
 Raphael Kelly
Raphael Kelly Security Analyst Team Lead, Varonis

Raphael Kelly, GCIH is a Team Lead for the Incident Response and Security Architecture team at Varonis. Raphael has an consulting and automation background with experience in IT infrastructure, Incident Response, and Data Protection. Varonis’ team of security professionals provide complementary Incident Response services to all existing customers. In addition, they work with customers to operationalize the Varonis Data Security Platform and integrate Varonis into the security ecosystem.

"A few months ago, a non-HR user opened up an HR folder that contained sensitive employee salary information. With Varonis, I was able to track down the user and review exactly what they had accessed and changed."

Infrastructure Manager, US Federal Credit Union

Want to see Varonis in action?

REQUEST A DEMO