Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT128
  • Created: 21st May 2025
  • Updated: 21st May 2025
  • Platform: Windows
  • Contributor: The ITM Team

Microsoft Purview eDiscovery

Investigators can leverage Microsoft Purview eDiscovery to proactively search for indicators of insider threat activity across Microsoft 365 workloads, including Exchange, SharePoint, OneDrive, and Teams. eDiscovery enables targeted, cross-tenant search of user communications and file activity, making it a powerful internal investigation and monitoring tool when used within approved workflows.

 

eDiscovery should be used to:

  • Identify data staging or policy violations involving sensitive or regulated information.
  • Investigate keywords, file types, or behavioral patterns linked to insider misuse.
  • Surface high-risk communication themes (e.g., resignation, exfil intent, coercion signals).
  • Correlate abnormal file sharing, email forwarding, or messaging activity across multiple users or services.

 

Detection Methods (via eDiscovery):

  • Keyword or Pattern-Based Search: Use search queries within eDiscovery to identify sensitive terms or behaviors, such as:

resign, job offer, backup, personal email, send to home, leaving soon, remotely wipe, compressed, file extensions commonly used for staging or exfiltration: .7z, .rar, .pst, .tar.gz, .gpg, or repeated references to external tools (e.g., “WeTransfer”, “Dropbox”, “Telegram”).

  • Targeted User Investigation: Investigate specific users flagged by UEBA, DLP, or HR triggers. Use Purview to search for mailbox forwarding rules or unusual email recipients, identify OneDrive or SharePoint activity involving external users or personal accounts, and retrieve deleted messages or files still available in preservation hold.
  • Communication Timeline Reconstruction: Use eDiscovery to build a timeline of internal communications and file interactions around suspicious dates—e.g., just before resignation, travel, or privileged access escalations.
  • Multi-Source Correlation: Cross-reference results from Exchange, Teams, OneDrive, and SharePoint in a single case. Link content types and time windows to identify coordinated behavior or quiet staging across services.

 

Indicators (via eDiscovery Results):

  • Discovery of sensitive files emailed to non-corporate domains.
  • Large compressed archives sent or shared shortly before account deactivation.
  • Coordinated message themes among multiple insiders (e.g., disgruntlement, collusion).
  • Use of keywords suggesting obfuscation, retaliation, or planned exit.
  • Evidence of Teams conversations involving encouragement or normalization of data misuse.

Sections

ID Name Description
AF030Message Deletion

The subject deletes digital communication records in order to remove evidence of prior activity, coordination, or intent. These records may include messages exchanged through collaboration platforms, internal messaging systems, or external communication applications.

 

Communication artifacts often provide investigators with critical context surrounding insider events, including planning, intent, and relationships between individuals. Deleting these records can reduce the available evidentiary timeline and hinder reconstruction of events.

 

Message deletion may occur before, during, or after an infringement. In some cases, subjects remove messages immediately after sending them to eliminate records of inappropriate requests or instructions. In other cases, deletion occurs after an alert, disciplinary action, or investigation has begun.

 

Because communication platforms often retain administrative logs of message deletion events, the act of deleting messages may itself become a significant investigative indicator.

PR041Credential Collection

A subject collects, copies, retrieves, exports, records, or stages credentials, secrets, keys, certificates, tokens, or other authentication material in preparation for later access or misuse. This behavior may involve credentials assigned to the subject, credentials assigned to another individual, shared credentials, service account credentials, or authentication material discovered in exposed locations such as tickets, repositories, documentation, configuration files, scripts, password managers, or secrets vaults.

 

Credential collection becomes a preparatory concern when the subject’s handling of authentication material exceeds their legitimate operational need or indicates future use outside approved access processes. The behavior may include saving credentials to local files, screenshots, notes, spreadsheets, personal password managers, clipboard history, removable media, or other locations where they can be reused later.

 

This preparation may precede unauthorized access, internal credential sharing, privilege misuse, data collection, sabotage, or anti-forensic measures to mislead attribution.

AF030.001Deletion of Corporate Communication Messages

The subject deletes messages from organization-managed communication platforms such as enterprise collaboration tools, internal messaging systems, or other corporate communication environments.

 

These platforms commonly contain operational discussions, requests for information, coordination between staff, or exchanges relating to sensitive work activities. Deleting messages from these systems may remove evidence of policy violations, improper instructions, or coordination with other individuals.

 

In many enterprise platforms, message deletion events generate administrative audit artifacts. While the message content may no longer be visible to users, deletion activity can often still be identified through platform audit logs, retention systems, or administrative investigation tools.

AF030.003Use of Disappearing or Self-Deleting Messages

A subject enables or uses a communication feature that automatically deletes messages after they are read, after a defined period, or when a conversation is closed, with the intention of reducing the communication evidence available to investigators.

 

The subject may use disappearing-message functionality within an approved corporate platform or through a non-corporate messaging application. Automatic deletion may be configured for an individual conversation, group, channel, workspace, or account. The subject may also change an existing conversation from persistent retention to temporary retention before exchanging information connected to an infringement.

 

This behavior differs from the manual deletion of corporate or non-corporate messages because the removal mechanism is established before or during the communication. Messages may disappear without a separate deletion action being performed after each message is sent.

 

Investigators should examine when the disappearing-message setting was enabled, who enabled it, the configured retention period, which participants were involved, and whether the setting was changed shortly before sensitive or suspicious communications occurred. The ordinary availability of an ephemeral messaging feature does not establish anti-forensic intent; classification should require evidence that the feature was deliberately used to reduce investigative visibility.

AF030.004Bulk Deletion of Message History

A subject deletes a substantial volume of messages, conversations, threads, channels, or communication history to remove or materially reduce the records available for investigation.

 

Bulk deletion may involve selecting and deleting multiple messages, repeatedly deleting individual messages within a short period, clearing an entire conversation, removing channel history, deleting archived communications, or using scripts, administrative tools, application programming interfaces, or automation to remove content at scale.

 

The behavior may occur after the subject becomes aware of an investigation, disciplinary process, access review, audit, legal dispute, or anticipated offboarding. It may also occur immediately before the subject conducts another infringement where prior communications could reveal planning, coordination, relationships, or intent.

 

The significance of bulk deletion should be assessed against the subject’s normal messaging activity, the amount of content removed, the time period affected, the platforms involved, and whether the deleted communications related to known subjects, external parties, sensitive projects, or active investigations.

 

Investigators should identify deletion event volume, timestamps, conversation identifiers, affected participants, client or application source, administrative actions, and any corresponding data preserved through retention or legal-hold systems.

AF030.005Administrative Deletion of Communication Messages

A subject uses administrative, moderation, ownership, compliance, or delegated platform privileges to delete messages created by another subject or to remove communication records from a shared organizational environment.

 

The subject may delete individual messages, conversation threads, channel content, direct-message history, group discussions, or entire communication spaces. Because the subject acts through an elevated or delegated role, the deletion may affect evidence belonging to several participants and may remove communications that the original author could not delete themselves.

 

This behavior may be used to conceal improper instructions, remove evidence of collusion, suppress complaints, protect another subject, or interfere with an active investigation. The administrative action may appear legitimate where the subject normally manages inappropriate content, retention, moderation, or workspace administration.

 

Investigators should assess whether the deletion was supported by an approved moderation, legal, records-management, or operational requirement. Relevant evidence includes the administrative identity used, the original message author, affected participants, deletion reason, approval records, platform audit logs, retention configuration, and the relationship between the deleting subject and those whose messages were removed.

 

The use of administrative privileges alone does not establish anti-forensic conduct. Classification should require evidence that the deletion was unauthorized or intended to remove evidence relevant to an insider event.

AF030.006Deletion of Communication Containers

A subject deletes a channel, group, workspace, conversation, mailbox folder, discussion board, or other communication container to remove the messages and associated context held within it.

 

Deleting a communication container may remove or obscure a larger body of evidence than deleting individual messages. The affected records may include message content, participant lists, timestamps, thread relationships, attachments, reactions, membership changes, and links to other organizational material.

 

The subject may delete the container after communications associated with an infringement have concluded, after participants have left the group, or after the subject becomes aware that the communication environment may be reviewed. They may also rename, archive, or move the container before deletion to make it more difficult to identify.

 

Investigators should establish who created, owned, administered, archived, and deleted the container; when the deletion occurred; which participants and messages were affected; and whether the activity followed an alert, complaint, investigation, or other relevant event. Platform audit records, retention systems, backups, legal holds, exports, and participant devices may allow the deleted content or surrounding metadata to be reconstructed.