Insider Threat Matrix™Insider Threat Matrix™
  • ID: DT040
  • Created: 01st June 2024
  • Updated: 01st June 2024
  • Contributor: The ITM Team

Microsoft Exchange Message Trace

Message trace is a feature within Exchange that permits the ability to identify inbound and outbound emails within the organization.

This can be used to see which mailboxes have sent or received emails, the time, the subject line, and recipients.

Sections

ID Name Description
IF010Exfiltration via Email

A subject uses electronic mail to exfiltrate data. This can be achieved through including data in the email subject line or body, or utilizing email attachments to send files.

IF021Harassment and Discrimination

A subject engages in unauthorized conduct that amounts to harassment or discriminatory behavior within the workplace, targeting individuals or groups based on protected characteristics, such as race, gender, religion, or other personal attributes. Incidents of harassment and discrimination may expose the organization to legal risks, potential reputational damage, and regulatory penalties. Additionally, individuals affected by such behavior may be at higher risk of retaliating or disengaging from their work, potentially leading to further insider risks.

MT020Ideology

A subject is motivated by ideology to access, destroy, or exfiltrate data, or otherwise violate internal policies in pursuit of their ideological goals.

 

Ideology is a structured system of ideas, values, and beliefs that shapes an individual’s understanding of the world and informs their actions. It often encompasses political, economic, and social perspectives, providing a comprehensive and sometimes rigid framework for interpreting events and guiding decision-making.

 

Individuals driven by ideology often perceive their actions as morally justified within the context of their belief system. Unlike those motivated by personal grievances or personal gain, ideological insiders act in service of a cause they deem greater than themselves.

IF036Misuse of Corporate Communication Channels

A subject uses organization-managed communication channels to send, distribute, or amplify messages that violate acceptable use expectations, undermine workplace safety, damage operational trust, or create legal, reputational, or personnel risk. This may occur through email, enterprise messaging platforms, collaboration tools, internal forums, ticketing systems, shared document comments, or other corporate communication environments.

IF041Unauthorized Organizational Representation

A subject falsely or improperly represents that they possess authority to speak, decide, approve, negotiate, instruct, certify, or make commitments on behalf of the organization. The subject uses their genuine association with the organization, their role, access to internal communication channels, or knowledge of organizational processes to make the representation appear legitimate.

 

Unauthorized Organizational Representation may occur through email, collaboration platforms, telephone calls, meetings, social media, customer communications, supplier negotiations, contractual discussions, regulatory engagement, public statements, or internal directives. The subject may claim authority they do not hold, act outside the limits of delegated authority, or omit information that would make the lack of authorization apparent.

 

The behavior may result in unauthorized commitments, misleading statements, improper instructions, reputational harm, financial liability, disclosure of protected information, disruption of established decision-making, or reliance by an internal or external party. A representation may be harmful even where the subject does not obtain access or impersonate another named individual.

 

This object differs from PR027 – Impersonation. Impersonation concerns adopting, fabricating, or misrepresenting identity to enable access or another planned action. Unauthorized Organizational Representation concerns misuse of actual or apparent institutional authority. Both objects may apply where the subject assumes another person’s identity and then issues instructions or commitments on behalf of the organization.

 

Investigators should examine delegated-authority records, approval requirements, communication history, signature blocks, meeting records, contractual limits, and whether recipients reasonably relied upon the representation.

PR050Trusted Relationship Cultivation

A subject deliberately develops a relationship of trust with a colleague, administrator, service provider, customer, or control owner to obtain future assistance, information, approval, or reduced scrutiny.

 

The conduct may involve repeatedly offering help, volunteering for tasks, creating dependency, demonstrating apparent reliability, or establishing informal communication outside approved processes. The relationship is later used to secure exceptional access, accelerate a request, obtain confidential information, bypass verification, or discourage challenge.

 

This would not classify ordinary professional relationship-building. Investigative relevance arises where the relationship is developed or exploited to enable a subsequent infringement.

IF044Abuse of Decision-Making Authority

A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.

 

The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.

 

This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.

 

This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right.

IF010.001Exfiltration via Corporate Email

A subject exfiltrates information using their corporate-issued mailbox, either via software or webmail. They will access the conversation at a later date to retrieve information on a different system.

IF010.002Exfiltration via Personal Email

A subject exfiltrates information using a mailbox they own or have access to, either via software or webmail. They will access the conversation at a later date to retrieve information on a different system.

PR015.003Email Forwarding Rule

The subject creates an email forwarding rule to transport any incoming emails from one mailbox to another.

AF027.001Email Deletion

The subject deliberately deletes emails - either sent, received, or both - with the intent to obstruct investigative visibility, remove evidence of policy violations, or eliminate traces of communication relevant to an insider event. While routine inbox maintenance is common, patterns of targeted deletion may indicate purposeful concealment.

IF036.004Extremist Communication Content

A subject distributes extremist, radicalizing, terrorist-supportive, or ideologically violent material through organization-managed communication channels. This may include propaganda, manifestos, violent ideological imagery, symbols associated with extremist organizations, recruitment material, or communications endorsing politically, religiously, racially, or ideologically motivated violence.

IF036.003Offensive Communication Content

A subject distributes offensive, graphic, obscene, degrading, or inflammatory material through organization-managed communication channels. This may include content that violates acceptable use expectations, disrupts workplace operations, damages team trust, or creates legal, reputational, or personnel risk.

IF036.002Inappropriate Sexual or Explicit Communications

A subject uses corporate communication channels to send, request, display, or distribute sexually explicit, obscene, or otherwise inappropriate material unrelated to legitimate business activity. This may include explicit images, sexualized comments, unwanted personal advances, or inappropriate jokes distributed through work systems.

IF036.001Hostile, Abusive, or Threatening Communications

A subject uses organization-managed communication channels to send hostile, abusive, coercive, intimidating, or threatening messages to another individual or group. This may include direct insults, aggressive language, repeated disparagement, intimidation, implied retaliation, coercive demands, or threats of professional, personal, or physical harm.

PR022.001Outbound Social Engineering via Email

A subject uses email to deceive, manipulate, or persuade another person into disclosing information, performing an action, approving a request, or enabling access that may support a later infringement. The subject may send messages from a corporate mailbox, personal account, spoofed address, compromised account, or third-party service in order to create a convincing pretext.

 

This behavior may involve impersonating a colleague, manager, vendor, customer, service provider, or trusted authority. The subject may use urgency, confidentiality, procedural familiarity, or organizational context to influence the recipient’s decision-making. The intended outcome may include obtaining credentials, internal process information, sensitive documents, access approvals, financial changes, or other information or actions that prepare the subject for further misuse.

PR022.002Outbound Social Engineering via Voice

A subject uses voice communication to deceive, pressure, or persuade another person into disclosing information, changing a control, approving access, or taking an action that may support a later infringement. This may occur through corporate telephony, mobile calls, voice over IP services, conference platforms, helpdesk calls, or external calling infrastructure.

 

This behavior may involve impersonation, false authority, urgency, familiarity, or procedural manipulation. The subject may contact service desk personnel, administrators, reception staff, colleagues, vendors, or other individuals who can influence access, identity verification, physical entry, operational processes, or administrative controls. The intended outcome may include account recovery, password reset assistance, disclosure of internal procedures, access approval, security exception handling, or other enabling action.

IF043.003Equipment or Facility Diversion

A subject redirects organizational equipment, vehicles, facilities, laboratories, production capability, or other physical assets toward an unauthorized use. Harm may include reduced availability, damage, operating cost, or disruption to legitimate activity.

IF044.001Unauthorized Approval

A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.

 

Examples include:

  • approving access for a favored individual without business justification
  • approving a supplier despite an undisclosed conflict
  • authorizing expenditure outside the intended purpose
  • approving an exception using false or incomplete supporting information

 

The defining evidence is an affirmative decision made through authority legitimately assigned to the subject.

IF044.002Improper Denial

A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.

 

Examples include:

  • denying a legitimate customer request because of a personal dispute
  • refusing an employee entitlement in retaliation
  • blocking a supplier or applicant to benefit an associate
  • rejecting an access request despite established eligibility
  • withholding an approval to exert pressure on another individual
IF044.003Improper Preferential Treatment

A subject uses decision-making authority to provide an unauthorized advantage to a person, organization, account, supplier, applicant, or other beneficiary.

 

Examples include:

  • prioritizing an associate’s application outside established criteria
  • granting favorable commercial terms without authorization
  • selecting a supplier because of an undisclosed personal relationship
  • allocating a scarce benefit contrary to the approved process
  • overlooking a requirement for a favored party while enforcing it against others
IF044.004Suppression of Escalation or Review

A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.

 

Examples include:

  • preventing a security concern from being referred to the appropriate team
  • closing a complaint without the required review
  • declining to escalate a report involving an associate
  • directing that an audit finding not be formally recorded
  • narrowing an investigation to exclude relevant conduct or evidence
IF044.005Unauthorized Waiver or Control Exception

A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.

 

Examples include:

  • waiving identity-verification requirements
  • exempting a transaction from secondary review
  • overriding a mandatory security or compliance check
  • allowing work to proceed despite an unmet control condition
  • approving an exception without recording the required rationale
IF044.006Unauthorized Prioritization or Deprioritization

A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.

 

Examples include:

  • moving an associate’s request ahead of others without justification
  • deliberately delaying a complaint until a deadline expires
  • deprioritizing a customer because of a personal disagreement
  • changing case urgency to avoid scrutiny or service obligations
  • accelerating a transaction so that required review cannot occur