Departing privileged admin staging data to personal cloud with signs of external coordination — legal hold, do-not-tip-off, chain-of-custody under pressure
A extremely-hard Cybersecurity scenario on Insider + External Collusion Data Theft.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 5 templates in this Track + Difficulty pool.
catalog id · insider-collusion-exfil-departing-admin
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Evidence-preserving insider-threat response
- Legal-hold and chain-of-custody discipline
- Exfiltration Over Web Service · ExfiltrationT1567 · TA0010MappedHigh confidence
Trains scoping of insider uploads to personal cloud storage.
- Exfiltration Over Physical Medium · ExfiltrationT1052 · TA0010MappedMedium confidence
Trains scoping of the USB-SSD copy channel.
- User Behavior AnalysisD3-UBAMappedHigh confidence
Trains behavior-baseline detection of abnormal bulk DB exports.
- User Account PermissionsD3-UAPMappedMedium confidence
Trains least-privilege scoping for a departing privileged DBA.
- Data Security · ProtectPR.DS · PRMappedHigh confidence
Trains the data-security lens on crown-jewel exfiltration.
- Continuous Monitoring · DetectDE.CM · DEMappedHigh confidence
Trains detection from DB-export and DLP telemetry.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains evidence-preserving, legally-aware insider triage.
- IR lifecycle phasePost-Incident ActivityMappedMedium confidence
Trains HR/Legal coordination and offboarding lessons-learned.
- Revoking Credentials for Departing Employees2.DMappedHigh confidence
Trains the departing-credentials baseline central to this case.
- Secure Sensitive Data2.IMappedMedium confidence
Trains the sensitive-data control under insider pressure.
- Data ProtectionControl 3MappedHigh confidence
Trains the data-protection control the exfil exercises.
- Account ManagementControl 5MappedHigh confidence
Trains the privileged-account lifecycle around separation.