Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF038
  • Created: 28th July 2026
  • Updated: 28th July 2026
  • Contributor: The ITM Team

Incremental Data Collection

A subject deliberately collects organizational data in small quantities over an extended period to reduce the likelihood of detection. Rather than performing a single high-volume download or export, the subject retrieves individual files, records, messages, or other data elements across multiple sessions, systems, or working days. Each retrieval may remain below conventional alerting thresholds and may appear consistent with legitimate activity when reviewed in isolation.

 

Incremental Data Collection may involve slowly downloading files from network shares or collaboration platforms, accessing individual customer records, executing repeated low-volume database queries, exporting small result sets, or retrieving data through an application programming interface. The cumulative activity may result in substantial unauthorized collection while avoiding detections that focus on mass downloads, unusual transfer rates, or short-term spikes in access.

 

The behavior is anti-forensic where the pacing, fragmentation, or distribution of activity is intended to obscure the overall scale of collection, hinder attribution, or prevent investigators from identifying a coherent pattern. Investigators should distinguish this behavior from routine low-volume access by examining cumulative activity over extended periods, changes in the subject's access pattern, the sensitivity and novelty of the data retrieved, and whether the collection aligns with the subject's role or established working practices.