Hillary fell victim to a spear phishing attack and her account credentials are now in the hands of a cyber-criminal named Boris.
We can identify network logon events from Hillary that don't come from her usual IP addresses and occur at odd times. We can detect unusual activity on password files and scripts, and when binaries are put in odd places. We can detect the presence of recon tools and malware on network drives. Since Hillary's account has been hijacked, this behavior deviates from her normal file and email access patterns, and triggers Varonis' alerts.
Back to all