preventions
- ID: PV049
- Created: 23rd April 2025
- Updated: 23rd April 2025
- Platforms: WindowsLinuxMacOS
- Contributor: The ITM Team
Managerial Approval
The process for having software installed on a corporate endpoint by IT should require approval from the employee's line manager to ensure the request is legitimate and appropriate.
Sections
| ID | Name | Description |
|---|---|---|
| PR010 | Software or Access Request | A subject may make a request for software (such as an RDP, SSH or FTP client) or access (such as USB mass storage device access) to be installed or enabled on a target system, to facilitate the infringement. |
| IF013 | Disruption of Business Operations | The subject causes interruptions, degradation, or instability in organizational systems, processes, or data flows that impair day‑to‑day operations and affect availability, integrity, or service continuity. This category encompasses non‑exfiltrative and non‑theft forms of disruption, distinct from data exfiltration or malware aimed at permanent destruction.
Disruptive actions may include misuse of administrative tools, intentional misconfiguration, suppression of services, logic interference, dependency tampering, or selective disabling of critical functions. The objective is operational impact; slowing, blocking, or misrouting workflows, rather than data removal or theft. |
| PR027.002 | Impersonation via Collaboration and Communication Tools | The subject creates, modifies, or misuses digital identities within internal communication or collaboration environments—such as email, chat platforms (e.g., Slack, Microsoft Teams), or shared document spaces—to impersonate trusted individuals or roles. This tactic is used to gain access, issue instructions, extract sensitive data, or manipulate workflows under the guise of legitimacy.
Impersonation in this context can be achieved through:
The impersonation may be part of early-stage insider coordination, privilege escalation attempts, or subtle reconnaissance designed to map workflows, bypass controls, or test detection thresholds.
Example Scenarios:
|
| AF022.001 | Use of a Virtual Machine | The subject uses a virtual machine (VM) on an organization device to contain artifacts of forensic value within the virtualized environment, preventing them from being written to the host file system. This strategy helps to obscure evidence and complicate forensic investigations. By running a guest operating system within a VM, the subject can potentially evade detection by security agents installed on the host operating system, as these agents may not have visibility into activities occurring within the VM. This adds an additional layer of complexity to forensic analysis, making it more challenging to detect and attribute malicious activities. |
| ME001.002 | Purchase and Use of Unmanaged Corporate Hardware | The subject purchases a laptop (or similar endpoint) using a corporate payment method but does so outside established procurement and provisioning processes. By bypassing IT and asset management workflows, the subject introduces a corporate-funded but unmanaged device into the environment.
Such devices often lack standard security controls—such as endpoint detection and response (EDR), encryption, configuration baselines, or patching—and may not be tracked in asset inventory systems. While the subject may rationalize the purchase as operationally necessary (e.g., urgency, convenience, or perceived lack of IT responsiveness), the result is a sanctioned but invisible device with the potential to bypass monitoring and governance controls.
This behavior undermines organizational asset control, complicates investigative attribution, and introduces unmanaged endpoints capable of accessing sensitive networks and data. |
| PR027.005 | Service Desk Impersonation for Credential Manipulation | The subject deliberately impersonates a member of the organization—typically a colleague, manager, or IT representative—or otherwise misrepresents themselves in order to manipulate service desk staff into resetting a password, unlocking an account, or granting access to a system. These requests are framed to appear legitimate and urgent, often exploiting common support workflows or pressure tactics (e.g., deadline stress, executive impersonation).
This behavior is especially dangerous because it abuses internal trust pathways and bypasses traditional authentication, detection, or technical controls. It can occur via phone, email, chat, or in-person interaction and is frequently used in preparation for unauthorized data access, surveillance, or exfiltration. |
| IF013.002 | Operational Disruption Impacting Customers | The subject deliberately interferes with operational systems in ways that degrade, interrupt, or misroute services relied upon by customers, without relying on file deletion or malware. This includes misconfigurations, service disabling, authentication interference, or intentional introduction of latency, instability, or incorrect outputs. The result is operational degradation that directly or indirectly affects service delivery, availability, or trust.
Unlike File or Data Deletion, this infringement does not depend on erasing data, and unlike Destructive Malware Deployment, it does not rely on malicious payloads or automated damage. The disruption instead stems from direct manipulation of infrastructure, configurations, service states, or user access.
Examples include:
These actions may be motivated by retaliation, concealment, sabotage, or insider coercion, and often occur in environments where the subject has legitimate system access but uses it to destabilize service delivery covertly. |
| IF016.012 | Fraudulent Refund Issuance | A subject abuses authorized access to create, approve, increase, duplicate, or redirect a refund without a legitimate business basis or required authorization.
The subject may issue the refund to themselves, a friend, family member, associate, colluding customer, or another external party. This may involve refunding a transaction that did not occur, issuing a refund where the goods or services remain valid, refunding more than the original amount, processing the same refund multiple times, or redirecting the proceeds to a payment method or account controlled by an unauthorized recipient.
The subject may conceal the infringement by creating fictitious customer complaints, manipulating return or cancellation records, using unrelated customer accounts, bypassing approval thresholds, dividing the value across multiple refunds, or recording false reasons for the transaction. |
| IF016.011 | Misappropriation of Redeemable Value | A subject abuses authorized access to create, issue, increase, transfer, or redeem value-bearing instruments or account-based benefits without a legitimate business purpose or required approval.
Redeemable value may include gift cards, promotional codes, vouchers, account credits, loyalty balances, refund credits, service credits, or similar benefits that can be exchanged for goods, services, discounts, or financial advantage.
The subject may direct the value to themselves, friends, family members, associates, colluding customers, or other external parties. The value may be provided without payment, sold, exchanged, or otherwise used for personal or third-party gain.
The subject may conceal the activity by using fictitious justifications, linking issuance to unrelated customer records, splitting value across multiple low-value transactions, remaining below approval thresholds, or repeatedly reissuing credits or codes. |
| IF043.001 | Personnel Diversion | A subject directs organizational personnel to perform work for an unauthorized purpose, beneficiary, or activity. Harm may include lost working time, delayed tasks, increased labour cost, or reduced operational capacity. |
| IF043.003 | Equipment or Facility Diversion | A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity. |
| IF043.004 | Inventory Diversion | A subject redirects organizational stock, materials, products, components, or consumable assets to an unauthorized recipient, destination, or purpose. Harm may include financial loss, stock discrepancies, supply shortages, or production delays. |
| MT021.001 | Conflicting Personal Relationship | A subject is influenced by a personal, familial, romantic, or close social relationship with an individual whose interests are affected by the subject’s organizational responsibilities.
The relationship may involve a colleague, applicant, customer, supplier representative, contractor, investigation subject, complainant, or another person connected to an organizational decision. The conflict may arise where the subject can approve access, influence recruitment, award work, alter a case outcome, disclose information, suppress scrutiny, or provide another form of preferential treatment.
The existence of a personal relationship does not itself establish harmful intent. The investigative concern arises where the relationship creates a material conflict with the subject’s duties and is not disclosed through the organization’s required process. Relevant indicators may include repeated favorable decisions, unusual access to information concerning the connected person, involvement in matters from which the subject should have recused themselves, or communications inconsistent with the stated professional relationship.
Investigators should establish the nature and timing of the relationship, the subject’s disclosure obligations, the decisions or access affected by it, and whether the subject took steps to conceal the connection. The resulting infringement may separately involve abuse of decision-making authority, unauthorized data access, data disclosure, fraud, or interference with an investigation. |
| MT021.002 | Conflicting Financial Interest | A subject holds an undisclosed financial interest in an organization, individual, transaction, investment, asset, or commercial outcome affected by their organizational responsibilities.
The interest may include company ownership, shares, debt, commission, referral payments, profit-sharing arrangements, creditor relationships, beneficial ownership, or another financial position through which the subject may gain or avoid loss. The interest may be held directly or indirectly through a family member, associate, trust, company, or other intermediary.
The conflict becomes operationally significant where the subject can influence procurement, supplier selection, pricing, investment decisions, contract awards, customer treatment, regulatory review, access permissions, or the handling of confidential information. The subject may favor a connected entity, suppress unfavorable information, disclose commercially useful material, or manipulate a decision while presenting their actions as ordinary professional judgment.
Investigators should identify the financial relationship, determine when it began, establish whether disclosure was required, and compare the subject’s decisions with objective organizational criteria. Evidence may include corporate ownership records, declared-interest registers, procurement records, payment data, communications, approval history, and repeated decisions benefiting the same external entity. |