detections
- ID: DT033
- Created: 31st May 2024
- Updated: 31st May 2024
- Contributor: The ITM Team
Closed-Circuit Television
CCTV can be used to observe activity within or around a site. This control can help to detect preparation or infringement activities and record it to a video file.
Sections
| ID | Name | Description |
|---|---|---|
| PR007 | CCTV Enumeration | The subject enumerates organizational CCTV coverage through physical reconnaissance, network-based probing, or a combination of both. This behavior aims to identify surveillance blind spots, coverage patterns, and system weaknesses in order to plan insider activity such as unauthorized entry, covert data removal, or sabotage.
When combined, physical and network enumeration provide a sophisticated map of surveillance infrastructure. For example, a subject may confirm camera placement through on-site observation, then validate viewing angles and live coverage zones by remotely accessing the corresponding camera feeds across the network. This dual approach allows the subject to identify exact surveillance gaps, test whether specific areas are monitored, and plan movement or concealment with high confidence.
This behavior is a strong indicator of deliberate preparation, as it requires technical effort, situational awareness, and intent to circumvent organizational surveillance. |
| PR008 | Physical Item Smuggling | A subject attempts to defeat physical security controls by smuggling an item (potentially an innocent item at first) into a controlled area to facilitate an infringement (such as a smart phone with a camera). |
| PR009 | Physical Exploration | A subject attempts to defeat physical security controls to gain access to a secured area to conduct an infringement. |
| IF003 | Exfiltration via Media Capture | Exfiltration via media capture refers to the extraction of sensitive information through the recording of visual or auditory content using capture mechanisms that operate outside organizational control. This includes the use of external devices, embedded system tools, or third-party applications to record screens, documents, or conversations and convert them into transferable media formats such as images, video, audio, or structured transcripts.
This category is defined not by the type of data being accessed, but by the method of extraction, specifically, the transformation of information into captured media in order to bypass conventional monitoring and control mechanisms. In these scenarios, the subject does not transfer files or data through approved or monitored channels. Instead, they reproduce the information in an alternate form that can be removed without generating traditional indicators of exfiltration.
Media capture techniques are particularly effective in environments where digital controls are mature, such as strong data loss prevention (DLP), restricted file transfer mechanisms, or monitored endpoints. As these controls limit conventional exfiltration paths, subjects may shift toward out-of-band capture methods that operate beyond system visibility.
This behavior may be opportunistic or deliberate. In lower-control environments, subjects may casually capture information with minimal consideration of detection. In higher-control environments, the use of media capture may indicate awareness of monitoring capabilities and an intentional effort to circumvent them. In both cases, the technique exploits a fundamental gap between information exposure and information control, once data is visible or spoken, it becomes inherently difficult to contain.
Media capture also varies in its execution and detectability. Some techniques are rapid and discrete, such as still photography, while others involve sustained collection, such as video recording or continuous audio capture.
From an investigative perspective, this section represents a class of behaviors where traditional telemetry is limited or absent. Detection often relies on indirect indicators, environmental controls, or post-event analysis of leaked material. As a result, prevention and deterrence play a critical role, particularly through physical controls, policy enforcement, and attribution mechanisms such as watermarking. This section is closely related to broader data loss behaviors, but is distinct in its reliance on out-of-band capture methods rather than direct data transfer . |
| IF002 | Exfiltration via Physical Medium | A subject may exfiltrate data via a physical medium, such as a removable drive. |
| ME013 | Media Capture | A subject can capture photos, videos and/or audio with an external device, such as taking photos of a screen, documents, or their surroundings. |
| IF012 | Public Statements Resulting in Brand Damage | A subject makes comments either in-person or online that can damage the organization's brand through association. |
| IF006 | Unauthorized Printing of Documents | A subject exfiltrates information by printing it to paper or other physical medium. |
| AF010 | Physical Removal of Disk Storage | A subject may remove attached disk storage from a system to deny investigators access to the files stored within it. |
| AF011 | Physical Destruction of Storage Media | A subject may destroy or otherwise impair physical storage media such as hard drives to prevent them from being analyzed. |
| PR012 | Physical Disk Removal | A subject removes the physical disk of a target system to access the target file system with an external device/system. |
| ME024 | Access | A subject holds access to both physical and digital assets that can enable insider activity. This includes systems such as databases, cloud platforms, and internal applications, as well as physical environments like secure office spaces, data centers, or research facilities. When a subject has access to sensitive data or systems—especially with broad or elevated privileges—they present an increased risk of unauthorized activity.
Subjects in roles with administrative rights, technical responsibilities, or senior authority often have the ability to bypass controls, retrieve restricted information, or operate in areas with limited oversight. Even standard user access, if misused, can facilitate data exfiltration, manipulation, or operational disruption. Weak access controls—such as excessive permissions, lack of segmentation, shared credentials, or infrequent reviews—further compound this risk by enabling subjects to exploit access paths that should otherwise be limited or monitored.
Furthermore, subjects with privileged or strategic access may be more likely to be targeted for recruitment by external parties to exploit their position. This can include coercion, bribery, or social engineering designed to turn a trusted insider into an active participant in malicious activities. |
| IF015 | Theft | A subject steals an item or items belonging to an organization, such as a corporate laptop or corporate mobile phone. |
| PR027 | Impersonation | The subject deliberately adopts or fabricates an identity—visually, digitally, or procedurally—to gain access, mislead stakeholders, or enable a planned insider event. Impersonation may occur in physical environments (e.g., unauthorized use of uniforms or cloned ID cards), digital platforms (e.g., email aliases or collaboration tools), or human interactions (e.g., job interviews). These behaviors typically precede unauthorized access, credential misuse, sabotage, or data exfiltration, and may allow subjects to operate without attribution or delay detection.
Impersonation is a high-risk preparatory behavior that often precedes direct misuse of trust. By assuming a false identity or misrepresenting role, authority, or affiliation, the subject gains unauthorized access or influence—without triggering traditional insider threat controls. |
| IF013 | Disruption of Business Operations | The subject causes interruptions, degradation, or instability in organizational systems, processes, or data flows that impair day‑to‑day operations and affect availability, integrity, or service continuity. This category encompasses non‑exfiltrative and non‑theft forms of disruption, distinct from data exfiltration or malware aimed at permanent destruction.
Disruptive actions may include misuse of administrative tools, intentional misconfiguration, suppression of services, logic interference, dependency tampering, or selective disabling of critical functions. The objective is operational impact; slowing, blocking, or misrouting workflows, rather than data removal or theft. |
| PR034 | Media Capture via External Device | The subject uses an external recording device, such as a personal mobile phone, tablet, wearable camera, or dedicated camera, to capture photographs, video, or audio of sensitive information displayed or stored within the organization’s environment.
This method is commonly used to collect information from computer screens, whiteboards, printed documents, internal dashboards, source code repositories, financial records, or physical access areas. The subject may position the device discreetly to photograph multiple screens, record walkthroughs of restricted areas, or document proprietary material during meetings or presentations. |
| PR036 | Hardware-Based Remote Access (IP-KVM) | A subject deploys a hardware-based remote access device, typically an IP-KVM (Keyboard, Video, Mouse over IP) system, to remotely interact with a workstation or server through its physical interfaces.
These devices connect directly to the system’s video output (HDMI or DisplayPort) and USB ports, capturing the display signal while injecting keyboard and mouse input remotely. The device presents itself to the operating system as standard USB Human Interface Devices (HID), such as a generic keyboard and mouse, allowing the subject to interact with the system as though physically present at the console.
Because the interaction occurs through physical interface emulation rather than installed software, activity generated through the device appears as local console input to the operating system. This can bypass controls designed to detect or restrict software-based remote access tools such as Remote Desktop Protocol (RDP) or third-party remote administration platforms.
Many IP-KVM devices provide independent network connectivity, including Ethernet, Wi-Fi, or cellular access, allowing the subject to maintain remote interaction with the system through an external management interface. When used in this manner, the remote session may not traverse corporate remote access infrastructure or generate conventional remote access/network logs.
While these devices have legitimate uses in system administration, hardware labs, and data center environments, a subject may deploy them covertly to maintain persistent remote access to a system without installing software or triggering typical remote access monitoring or network controls.
Within the Insider Threat Matrix, this behavior represents preparatory activity, as it establishes a covert remote control capability that may later enable unauthorized access, data exfiltration, or system manipulation. |
| ME031 | Unmanaged Device Presence | A subject operates in an environment where non-corporate, unmanaged devices can be introduced, carried, or used within organizational premises without effective restriction, monitoring, or control. These devices may include personal laptops, removable media, mobile phones, or small-form hardware capable of storage, processing, or network connectivity. Unlike sanctioned Bring Your Own Device (BYOD) arrangements, this condition exists outside formal governance, with no enforced linkage between the device and the subject's identity or role.
The presence of unmanaged devices establishes a persistent and unmonitored means through which a subject may bypass established security controls. This includes enabling offline data collection, covert data exfiltration, unauthorized recording, or the introduction of rogue systems. It also supports preparatory activity, such as staging data for removal or facilitating external interaction beyond controlled organizational channels. |
| IF030 | Exfiltration via SMS/MMS | A subject uses native mobile text messaging services, specifically Short Message Service (SMS) and Multimedia Messaging Service (MMS), to transmit sensitive organizational data to an external recipient. This behaviour enables data exfiltration through telecom-based channels that operate outside standard enterprise monitoring, logging, and data loss prevention controls.
Exfiltration via SMS is generally constrained to low-volume, text-based data such as credentials, contact lists, internal identifiers, or short excerpts of sensitive content. MMS expands this capability by allowing the transmission of images, screenshots, audio, or video, enabling higher-density data transfer including photographs or recordings of sensitive systems, documents, or physical environments.
The use of telecom-based messaging for data exfiltration presents significant investigative challenges. Evidence is frequently limited to device-level artifacts or external carrier records, which may be difficult to obtain. As such, this behaviour represents a high-risk exfiltration vector due to its low detectability, minimal technical barriers, and ability to bypass established security controls. |
| IF031 | Unauthorized Presence in Restricted Physical Areas | A subject deliberately enters or remains within a physical area as a trespasser, knowing they are not authorized to be present, where that presence alone creates a credible risk of harm to the organization.
|
| PR039 | Observational Information Gathering | The subject gathers sensitive, restricted, or operationally relevant information by observing others as they perform tasks, access systems, or handle data. This behavior allows the subject to obtain knowledge that is not formally available to them through their assigned role, access permissions, or authorized channels.
Observation may occur in both covert and overt forms, and the boundary between the two is often fluid.
Covert observation involves the subject acquiring information without the awareness of the observed individual. This includes:
Overt observation involves the subject obtaining information through socially facilitated or procedural means, often under a legitimate or benign pretext. This includes:
The information gathered may include:
This behavior serves as a foundational preparatory technique, supporting a wide range of downstream actions including unauthorized access, impersonation, data exfiltration, or policy circumvention. |
| IF037 | Physical Sabotage | A subject physically interferes with organizational equipment, infrastructure, facilities, or operational assets with the intent to cause damage, disruption, degradation, outage, safety risk, or loss of service. This infringement includes direct physical actions against systems or supporting infrastructure, such as disconnecting cables, interrupting power, damaging equipment, or impairing facility services required for normal operations. |
| PR045 | Unauthorized Hardware Introduction | A subject introduces, connects, installs, or positions unauthorized hardware within an organizational environment to establish a capability that may support a later infringement.
The hardware may provide network access, input capture, command execution, communications, surveillance, remote connectivity, or direct interaction with organizational systems. Examples include rogue network devices, hardware keyloggers, malicious peripheral devices, modified cables, portable computing devices, network taps, and embedded hardware implants.
Investigators should assess the device’s function, connection method, placement, ownership, configuration, communication activity, and the subject’s legitimate requirement to possess or deploy it. Particular attention should be given to hardware connected to sensitive systems, concealed from routine inspection, configured to communicate externally, or introduced outside approved procurement, asset management, and change control processes. |
| IF041 | Unauthorized Organizational Representation | A subject falsely or improperly represents that they possess authority to speak, decide, approve, negotiate, instruct, certify, or make commitments on behalf of the organization. The subject uses their genuine association with the organization, their role, access to internal communication channels, or knowledge of organizational processes to make the representation appear legitimate.
Unauthorized Organizational Representation may occur through email, collaboration platforms, telephone calls, meetings, social media, customer communications, supplier negotiations, contractual discussions, regulatory engagement, public statements, or internal directives. The subject may claim authority they do not hold, act outside the limits of delegated authority, or omit information that would make the lack of authorization apparent.
The behavior may result in unauthorized commitments, misleading statements, improper instructions, reputational harm, financial liability, disclosure of protected information, disruption of established decision-making, or reliance by an internal or external party. A representation may be harmful even where the subject does not obtain access or impersonate another named individual.
This object differs from PR027 – Impersonation. Impersonation concerns adopting, fabricating, or misrepresenting identity to enable access or another planned action. Unauthorized Organizational Representation concerns misuse of actual or apparent institutional authority. Both objects may apply where the subject assumes another person’s identity and then issues instructions or commitments on behalf of the organization.
Investigators should examine delegated-authority records, approval requirements, communication history, signature blocks, meeting records, contractual limits, and whether recipients reasonably relied upon the representation. |
| IF042 | Deliberate Safety Control Defeat | A subject disables, bypasses, overrides, falsifies, or prevents the operation of a safety control, resulting in an unsafe condition, exposure, near miss, injury, environmental impact, or damage to equipment.
Safety controls may be physical, procedural, mechanical, digital, or administrative. Examples include bypassing an interlock, falsifying an inspection, suppressing an alarm, overriding a maintenance restriction, or returning unsafe equipment to service.
The observable harm may include actual injury or damage, but it should not require it. A documented unsafe condition or near miss caused by the subject’s act is itself a concrete adverse outcome. |
| IF044 | Abuse of Decision-Making Authority | A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.
The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.
This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.
This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right. |
| IF003.002 | Exfiltration via External Device Video Capture | A subject records sensitive information by capturing video using an external device, such as a personal mobile phone or standalone camera. This behavior typically involves filming screens, documents, or physical environments where sensitive information is displayed or discussed.
Unlike software-based screen recording or screenshot tools, this method operates outside corporate control boundaries. The capture process occurs entirely outside the monitored endpoint, bypassing data loss prevention (DLP), endpoint detection, and audit logging mechanisms.
This technique is commonly observed in controlled environments where digital exfiltration is restricted or heavily monitored. It may be opportunistic (such as quickly recording a screen) or deliberate, involving repeated capture of large volumes of information over time. The use of an external device can indicate subject awareness of monitoring controls and an intent to avoid traceable data transfer. |
| IF003.001 | Exfiltration via Photography | A subject captures sensitive information by taking still images using an external device, most commonly a personal mobile phone. This typically involves photographing screens, printed documents, whiteboards, or other visual representations of sensitive data within the organization’s environment.
Unlike video capture, photography enables rapid, low-friction extraction of discrete information with minimal dwell time. A subject can capture high volumes of content in short bursts without sustained or conspicuous behavior, making this technique particularly effective in environments with physical proximity to sensitive material but strong digital controls.
This method often operates entirely outside controlled systems and therefore bypasses endpoint monitoring, data loss prevention (DLP), and network-based detection mechanisms. It is frequently opportunistic, occurring during routine access to sensitive information, but may also be deliberate, such as systematically photographing documents, screens, or workflows over time.
Photography-based exfiltration is especially prevalent in environments where:
The presence of this behavior may indicate awareness of monitoring controls or a preference for low-risk, low-detectability exfiltration methods. |
| IF003.003 | Exfiltration via Audio Capture | A subject captures sensitive information by recording audio using an external device, most commonly a personal mobile phone or wearable device. This typically involves recording conversations, meetings, phone calls, or ambient discussions where sensitive information is disclosed verbally.
Unlike visual capture techniques, audio capture does not require direct interaction with systems or documents. It enables the subject to collect information passively, often without needing to position a device toward a specific target. As a result, this method can be sustained over longer periods with reduced risk of detection, particularly in collaborative or discussion-heavy environments.
This technique operates entirely outside corporate monitoring controls, bypassing endpoint telemetry, data loss prevention (DLP), and access logging. It is particularly effective in environments where sensitive information is frequently communicated verbally, including meetings, support operations, incident response discussions, executive briefings, and informal conversations between colleagues.
Audio capture is often deliberate, as it requires forethought to record and later process the information. However, it may also be opportunistic, especially where subjects are routinely exposed to sensitive discussions. The presence of this behavior may indicate an intent to capture information that is not otherwise accessible in written or exportable form. |
| IF011.002 | Intentionally Weakening Physical Security Controls For a Third Party | The subject intentionally weakens or bypasses physical security controls for a third party, such as allowing them to piggyback into a secure area, leaving a door unlocked for them, or providing them with a security pass. |
| IF002.005 | Exfiltration via Physical Documents | A subject tansports physical documents outside of the control of the organization. |
| ME021.003 | Physical Access Credentials | Physical security credentials, such as an ID card or physical keys, that were available to the subject during employment are not revoked and can still be used. |
| IF015.004 | Theft of Non-Digital Assets | A subject steals non-digital assets, such as physical documents, belonging to an organization. |
| IF015.003 | Theft of Other Digital Assets | A subject steals other digital assets, such as monitors, hard drives, or peripherals, belonging to an organization. |
| IF015.002 | Theft of a Corporate Mobile Phone | A subject steals a corporate mobile phone belonging to an organization. |
| IF015.001 | Theft of a Corporate Laptop | A subject steals a corporate laptop belonging to an organization. |
| IF002.008 | Exfiltration via USB to Mobile Device | The subject uses a USB cable, and any relevant software if required, to transfer files or data from one system to a mobile device. This device is then taken outside of the organization's control, where the subject can later access the contents. |
| IF002.009 | Exfiltration via Disk Media | A subject exfiltrates data using writeable disk media. |
| ME024.004 | Access to Physical Hardware | Subjects with physical access to critical hardware—such as data center infrastructure, on-premises servers, network appliances, storage arrays, or specialized equipment like CCTV and alarm systems—represent a significant insider threat due to their ability to bypass logical controls and interact directly with systems. This level of access can facilitate a wide range of security compromises, many of which are difficult to detect through conventional digital monitoring.
Physical access may also include proximity to sensitive areas such as network closets, on-premises server racks, backup repositories, or control systems in operational technology (OT) environments. In high-security settings, even brief unsupervised access can be exploited to compromise system integrity or enable ongoing unauthorized access.
With this type of access, a subject can:
In operational environments, subjects with access to physical control systems (e.g., ICS/SCADA components, industrial HMIs, or IoT gateways) may alter processes, cause service disruptions, or create safety hazards. Similarly, access to CCTV or badge systems may allow them to erase footage, monitor employee movements, or manipulate access control logs.
Subjects with this form of access represent an elevated risk, especially when combined with technical knowledge or administrative privileges. The risk is compounded in environments with limited physical security controls, inadequate logging of physical entry, or weak segmentation between physical and digital assets. |
| ME024.005 | Access to Physical Spaces | Subjects with authorized access to sensitive physical spaces—such as secure offices, executive areas, data centers, SCIFs (Sensitive Compartmented Information Facilities), R&D labs, or restricted zones in critical infrastructure—pose an increased insider threat due to their physical proximity to sensitive assets, systems, and information.
Such spaces often contain high-value materials or information, including printed sensitive documents, whiteboard plans, authentication devices (e.g., smartcards or tokens), and unattended workstations. A subject with physical presence in these locations may observe confidential conversations, access sensitive output, or physically interact with devices outside of typical security monitoring.
This type of access can be leveraged to:
Subjects in roles that involve frequent presence in sensitive locations—such as cleaning staff, security personnel, on-site engineers, or facility contractors—may operate outside the scope of standard digital access control and may not be fully visible to security teams focused on network activity.
Importantly, individuals with this kind of access are also potential targets for recruitment or coercion by external threat actors seeking insider assistance. The ability to physically access secure environments and passively gather high-value information makes them attractive assets in coordinated attempts to obtain or compromise protected information.
The risk is magnified in organizations lacking comprehensive physical access policies, surveillance, or cross-referencing of physical and digital access activity. When unmonitored, physical access can provide a silent pathway to support insider operations without leaving traditional digital footprints. |
| ME025.001 | Proximity to Strategic Business Functions | A subject’s placement within critical business units or specialized teams can grant them access to highly sensitive operational data, strategic initiatives, and proprietary information. Roles within departments such as executive leadership, corporate strategy, legal, finance, R&D, supply chain management, and security operations position the subject to interact with confidential communications, forward-looking business plans, and strategic decision-making processes.
Subjects in close proximity to organizational leadership—including C-suite executives, senior directors, or key decision-makers—are uniquely positioned to access sensitive insights, manipulate decision-making, or gather intelligence on high-stakes initiatives. These individuals may be exposed to:
Having direct or indirect access to leaders facilitates eavesdropping on confidential conversations and provides early awareness of business initiatives. This proximity allows the subject to assess organizational vulnerabilities or identify high-value targets for insider exploitation. Furthermore, the subject may be positioned to:
Subjects in such positions hold considerable power to shape business outcomes—both through direct influence over strategic initiatives and by gaining early insights into organizational direction, which can be exploited for personal gain, external manipulation, or other malicious intents.
Additionally, such individuals may become targets for recruitment by external entities seeking to exploit their access to confidential business data or influence over strategic decisions. Their proximity to leadership and critical business functions makes them an ideal conduit for conducting insider threats on behalf of external adversaries. |
| ME025.002 | Leadership and Influence Over Direct Reports | A subject with a people management role holds significant influence over their direct reports, which can be leveraged to conduct insider activities. As a leader, the subject is in a unique position to shape team dynamics, direct tasks, and control the flow of information within their team. This authority presents several risks, as the subject may:
In addition to these immediate risks, subjects in people management roles may also have the ability to recruit individuals from their team for insider activities, subtly influencing them to support illicit actions or help cover up their activities. By fostering a sense of loyalty or manipulating interpersonal relationships, the subject may encourage compliance with unethical actions, making it more difficult for others to detect or challenge the behavior.
Given the central role that managers play in shaping team culture and operational practices, the risks posed by a subject in a management position are compounded by their ability to both directly influence the behavior of others and manipulate processes for personal or malicious gain. |
| PR027.001 | Deepfake or Synthetic Identity Use in Hiring | The subject leverages synthetic identity elements, AI-generated visuals, deepfake video, or falsified credentials to obtain employment or contractor status under a false identity. This tactic is commonly used to gain insider access to an organization while avoiding standard background checks, attribution mechanisms, or compliance controls.
Common methods include:
This tactic is particularly dangerous when used to embed individuals in sensitive roles such as DevOps, system administration, SOC analyst, or software engineering, where access to production systems and intellectual property is granted shortly after onboarding.
Example Scenarios:
|
| PR027.003 | Physical Impersonation Through Dress, Uniforms, or Appearance | The subject deliberately alters their physical appearance to resemble an authorized individual or category of personnel—such as employees, contractors, vendors, maintenance staff, or delivery personnel—in order to bypass physical security measures and gain access to restricted areas. This tactic relies on exploiting visual trust cues (e.g., uniforms, badges, company branding) and is often used during reconnaissance or access staging phases prior to an insider event.
Common methods include:
Example Scenarios:
|
| PR027.004 | Cloning or Forging ID Cards for Physical Access | The subject obtains, clones, fabricates, or otherwise manipulates physical access credentials—such as RFID cards, NFC badges, magnetic stripes, or printed ID cards—to gain unauthorized access to secure areas. This behavior typically occurs during early-stage preparation for insider activity and enables covert physical entry without triggering standard identity-based access controls.
Badge cloning can be performed using low-cost, widely available tools that can read and emulate access credentials. Forged ID cards are often visually convincing and used to bypass casual visual verification by staff or security personnel.
Example Scenarios:
|
| IF013.002 | Operational Disruption Impacting Customers | The subject deliberately interferes with operational systems in ways that degrade, interrupt, or misroute services relied upon by customers, without relying on file deletion or malware. This includes misconfigurations, service disabling, authentication interference, or intentional introduction of latency, instability, or incorrect outputs. The result is operational degradation that directly or indirectly affects service delivery, availability, or trust.
Unlike File or Data Deletion, this infringement does not depend on erasing data, and unlike Destructive Malware Deployment, it does not rely on malicious payloads or automated damage. The disruption instead stems from direct manipulation of infrastructure, configurations, service states, or user access.
Examples include:
These actions may be motivated by retaliation, concealment, sabotage, or insider coercion, and often occur in environments where the subject has legitimate system access but uses it to destabilize service delivery covertly. |
| IF037.001 | Physical Disconnection of Data or Communications Infrastructure | A subject physically disconnects, removes, loosens, or tampers with data or communications infrastructure to degrade, interrupt, or prevent organizational operations. This may include network cabling, fiber links, patch panel connections, transceivers, telecommunications cabling, console cables, storage interconnects, or monitoring and telemetry data feeds. |
| IF037.002 | Sabotage of Power Infrastructure | A subject physically interrupts, disables, damages, manipulates, or interferes with electrical power systems that support organizational equipment, facilities, or operations. This may include pulling power leads, powering off equipment, switching off rack power distribution units, tripping breakers or isolators, damaging power supply units, tampering with UPS systems, interfering with generators, or damaging electrical distribution equipment. |
| IF037.003 | Physical Damage to IT, Communications, or Operational Equipment | A subject physically damages, destroys, contaminates, obstructs, or degrades organizational equipment to impair availability, integrity, monitoring, safety, or operational capability. This may include damage to switches, routers, servers, firewalls, storage devices, endpoints, mobile devices, telecommunications equipment, racks, ports, connectors, screens, removable media, sensors, or monitoring devices. |
| IF037.004 | Sabotage of Facility Support Systems | A subject physically interferes with non-power facility systems that support organizational operations, safety, security, continuity, or environmental stability. This may include HVAC systems, cooling systems, fire suppression systems, water systems, environmental controls, communications risers, cable ducts, plant-room systems, or facility infrastructure supporting production, warehousing, laboratory, or operational spaces. |
| PR022.004 | Outbound Social Engineering via In-Person Interaction | A subject uses direct face-to-face interaction to deceive, manipulate, pressure, or persuade another person into disclosing information, granting access, overlooking a control, or performing an action that may support a later infringement. This behavior may occur in offices, reception areas, secure facilities, shared workspaces, events, meetings, or other physical environments where the subject can influence another person through direct conversation.
This behavior may involve impersonation, confidence-building, exploitation of familiarity, false authority, urgency, distraction, or procedural manipulation. The subject may target reception staff, security personnel, colleagues, managers, contractors, vendors, or visitors depending on the access or information required. The intended outcome may include physical entry, badge-assisted access, disclosure of internal procedures, access approval, document retrieval, system use, or the weakening of a control through interpersonal influence. |
| IF043.001 | Personnel Diversion | A subject directs organizational personnel to perform work for an unauthorized purpose, beneficiary, or activity. Harm may include lost working time, delayed tasks, increased labour cost, or reduced operational capacity. |
| IF043.003 | Equipment or Facility Diversion | A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity. |
| IF043.004 | Inventory Diversion | A subject redirects organizational stock, materials, products, components, or consumable assets to an unauthorized recipient, destination, or purpose. Harm may include financial loss, stock discrepancies, supply shortages, or production delays. |
| IF043.005 | Working-Time Diversion | A subject deliberately uses substantial paid working time for sustained activity unrelated to their organizational responsibilities. This should exclude minor personal use permitted under the Acceptable Use Policy. |
| IF031.001 | Unauthorized Presence in Data Center or Communications Areas | A subject deliberately enters or remains within a data center, server room, network operations area, telecommunications room, cable distribution area, or other restricted environment containing critical information technology or communications infrastructure without authorization to be present.
The subject’s proximity may provide direct access to servers, storage systems, network appliances, cabling, console interfaces, removable media, environmental controls, or out-of-band management equipment. The infringement applies where the subject knowingly crosses an established physical boundary, regardless of whether they subsequently interact with the equipment. |
| IF031.002 | Unauthorized Presence in Security Operations Areas | A subject deliberately enters or remains within a Security Operations Center, incident response room, insider threat investigation area, physical security control room, crisis-management room, or other restricted security operations environment without authorization.
Presence in these areas may expose active alerts, investigative information, subject identities, security architecture, surveillance feeds, response plans, detection capabilities, access credentials, or operational discussions. The subject does not need to interact with a security system or obtain a copy of information; unauthorized proximity to visible or audible security operations is sufficient for the infringement. |
| IF031.003 | Unauthorized Presence in Executive or Board Areas | A subject deliberately enters or remains within an executive office, boardroom, senior leadership meeting space, executive support area, or other restricted location used for confidential organizational decision-making without authorization.
The subject’s presence may expose strategic discussions, merger or acquisition information, financial results, legal advice, personnel decisions, security matters, executive schedules, authentication material, or confidential documents. The infringement applies even where the subject does not remove information or interrupt the meeting, because unauthorized observation or proximity may compromise sensitive organizational matters. |
| IF031.004 | Unauthorized Presence in Research, Laboratory, or Production Areas | A subject deliberately enters or remains within a restricted research facility, laboratory, prototype area, test environment, manufacturing floor, production line, formulation area, engineering workspace, or other location containing sensitive development or operational activity without authorization.
The area may expose unreleased intellectual property, prototypes, formulas, samples, research data, specialized equipment, manufacturing methods, safety-critical processes, or regulated materials. The subject’s presence may create risks to confidentiality, product integrity, safety, regulatory compliance, or operational continuity even where no additional action is observed. |
| IF031.005 | Unauthorized Presence in Records or Evidence Storage Areas | A subject deliberately enters or remains within an area used to store physical records, legal files, personnel documents, investigative material, evidential items, archived media, regulated records, or chain-of-custody material without authorization.
Unauthorized presence may expose confidential information or provide an opportunity to inspect, remove, substitute, contaminate, damage, or interfere with stored material. The infringement applies where the subject knowingly enters the controlled area, even where subsequent access to a specific record or evidential item cannot be established. |
| IF031.006 | Remaining in a Restricted Area Outside Authorized Hours | A subject knowingly remains within a restricted physical area after their authorized access period has ended, or enters the area during a time when their role, assignment, escort approval, or access authorization does not permit their presence.
The subject may have legitimate daytime or task-based access to the location, but that authority does not extend to the time at which the presence occurs. Relevant behaviors include remaining after a shift or escorted visit, entering during a closed period, concealing continued presence after other personnel depart, or returning outside an approved access window.
The infringement is distinguished from accidental overstay by evidence that the subject understood the temporal restriction and deliberately remained or entered regardless. |
| PR009.001 | Restricted Area Reconnaissance | A subject observes, explores, or informally surveys access routes, entrances, barriers, internal layouts, staffing patterns, and operational routines associated with a restricted physical area.
The subject may seek to identify which doors are badge-controlled, when an area is unattended, how visitors are processed, whether personnel challenge unfamiliar individuals, or where movement is not covered by security personnel or closed-circuit television. The activity may appear innocuous in isolation, but repeated or unexplained observation can indicate preparation for unauthorized entry, theft, sabotage, data access, or another physical infringement. |
| PR009.002 | Identification of Unsecured Physical Assets | A subject searches for or identifies physical assets that are unattended, insufficiently secured, or accessible outside normal control processes.
These assets may include laptops, removable media, physical identity tokens, keys, printed records, unlocked cabinets, exposed network ports, backup media, prototype equipment, or devices left in shared or low-occupancy areas. The subject may test whether an asset can be handled, removed, connected to, photographed, or accessed without attracting attention.
This behavior is operationally relevant where it indicates that the subject is identifying opportunities that could later support theft, credential misuse, unauthorized system access, data loss, or physical sabotage. |
| PR009.003 | Entry and Exit Route Reconnaissance | A subject identifies or assesses routes through which they or another person could enter, leave, or move through an organizational facility while reducing the likelihood of challenge or detection.
The subject may observe loading areas, emergency exits, service corridors, shared tenant spaces, stairwells, parking access points, delivery entrances, maintenance routes, or locations with limited physical security coverage. They may also assess whether doors are routinely propped open, whether exit routes permit re-entry, or whether movement between zones can occur without an additional credential check.
The behavior may indicate preparation to bypass normal entry controls, facilitate unauthorized third-party access, remove assets, or move between restricted areas without creating a complete access record. |
| PR009.004 | Security Patrol Pattern Observation | A subject observes the timing, route, frequency, staffing, or behavior of physical security patrols to identify periods or locations where monitoring is reduced.
The subject may repeatedly remain near patrol routes, note when security personnel enter or leave an area, track shift changes, observe response times, or determine whether patrols follow predictable schedules. They may also identify areas that are checked only intermittently or periods when security personnel are occupied elsewhere.
This behavior can support later unauthorized presence, theft, sabotage, tampering, or access to sensitive areas by allowing the subject to act during a predictable gap in physical oversight. |
| PR040.002 | Testing Access Controls | A subject attempts to access a system, repository, application, physical area, account, record set, or other restricted resource to determine whether the applicable access control prevents entry or generates a response.
The subject may use their own identity to request or attempt access slightly outside their normal responsibilities, test an expired or unauthorized physical identity token, navigate directly to a restricted application resource, or attempt to view information associated with another team, customer, case, or business function.
The action may be deliberately limited so that it can be described as accidental if challenged. Repeated denied attempts, access testing across several resources, or a later successful entry may indicate that the subject is mapping authorization boundaries before conducting unauthorized access or another infringement. |
| PR040.005 | Testing Physical Security Controls | A subject performs a limited physical action to determine whether access controls, security personnel, surveillance, visitor procedures, alarms, or other physical safeguards prevent or identify unauthorized presence.
The subject may test a restricted door, present a credential at an unauthorized area, follow another person through a controlled entrance, remain in an area after their approved access period, or enter a sensitive location without a clear operational reason. They may also observe whether security personnel challenge unfamiliar subjects or whether physical access violations generate follow-up activity.
The behavior is distinct from general physical exploration because the subject actively interacts with or crosses a security boundary to evaluate the result. The test may support later unauthorized entry, physical sabotage, theft, access to infrastructure, or facilitation of another person’s presence. |