Demo Center Home  >  Insider Threat Detection Demo

Use Cases

INSIDER THREAT DETECTION

See both sides of insider risk in one interactive demo: a trusted contractor whose infected device exposed active sessions, and a fraudulent IT candidate uncovered before they were ever granted access.
Both start from recaptured criminal underground data.

Insider Threat Protection by SpyCloud

     
       

Explore two chapters in one demo: a negligent contractor exposed by infostealer malware,
and a malicious candidate investigated for remote IT worker fraud.

What you'll see

Two kinds of insider risk, one data source

This demo has two chapters.

The first follows a compromised but well-meaning contractor whose infected personal device exposed workforce logins and active sessions,
and watch how SpyCloud remediates the exposure automatically.

The second follows a suspicious job candidate from a single email address to a confirmed remote IT worker fraud pattern,
investigated before access is ever granted.

Pick a chapter from the demo, and each runs in your browser. The same recaptured criminal underground data powers both,
whether the risk is a negligent exposure that already happened or a fraudulent identity trying to cause harm get in.

One data source. Session cookies, authentication tokens, MFA codes, and credentials recaptured from the criminal underground.

Chapter 1 · Already exposed

The negligent contractor


Detection

Infected device surfaces in console


Expansion

Logins and sessions exposed by one infection


Mapping

Blast radius across reachable accounts


Revocation

Password reset, session revoked server-side

Confirmation

Contained before behavior surfaced

Already exposed Never granted access

Chapter 2 · Never granted access

The malicious candidate


Investigate

One email address opens the case


Search

Unusual password patterns surface


Pivot

A shared VPN IP tied to DPRK activity


Connect

A network of aliases and personas


Corroborate

Reused passwords, shared machines

Conclude

Fraud indicators scored as strong

One data source caught both: the contractor who was compromised and the candidate who was never real.

HOW IT WORKS

Recapture, correlate, surface, route

SpyCloud's insider threat detection finds negligent, compromised, and malicious insiders using recaptured criminal underground data, from pre-hire screening through employment and offboarding.

STEP 1

Recapture

SpyCloud pulls session cookies, authentication tokens, MFA codes, and credentials from the criminal underground.

STEP 2

Correlate

SpyCloud links every recaptured artifact back to the employee, contractor, or candidate who owns it.

STEP 3

Surface

SpyCloud flags the exposure or the fraudulent identity pattern before any behavior turns anomalous.

STEP 4

Route

Your IdP, SOC, and HR workflows receive the signal through the SpyCloud API and act on it.

See how SpyCloud surfaces negligent, compromised, and malicious insiders from one data source.

Explore insider threat identification

Outcomes of Insider Threat Detection

What the data behind this demo shows

97%

of security professionals concerned about negligent and malicious insider threats

40%

of 2025 infostealer infections hit endpoints with EDR or antivirus installed

1T

recaptured identity assets SpyCloud searches per investigation

Check Your Exposure

See what recaptured criminal underground data already ties to your own domain.
Check Your Exposure for a fast read on your workforce identity risk.

Insider Threat Detection Demo FAQs

A negligent insider puts the organization at risk without intending to, usually by falling for a phishing attack, reusing a weak password, or working on a personal or managed device infected with infostealer malware. A compromised insider is a legitimate employee whose credentials or session tokens have been stolen by an external attacker who then uses that access while the employee remains unaware. A malicious insider deliberately misuses access for gain or harm, including a fraudulent candidate who uses a stolen or fabricated identity to get hired in the first place. According to the SpyCloud 2025 Insider Threat Pulse Report, 97% of security professionals are concerned about negligent insider threats and 93% about malicious ones. Behavioral tools catch patterns only after access is misused, so all three can move undetected during the window between compromise and detectable behavior, which is the gap SpyCloud closes with recaptured criminal underground data.

A password reset invalidates the password, but it does not end an active session. Attackers steal active session cookies and authentication tokens that let them walk past login entirely, so a stolen session stays valid after the password changes and bypasses multifactor authentication. Full remediation has to reset the exposed password and revoke the active session together. SpyCloud Identity Guardians does both, resetting the password and triggering server-side session revocation through Active Directory, Microsoft Entra ID, or Okta Workforce so the exposed access is actually cut off.

Infostealer malware silently harvests everything tied to a device, including saved passwords, session cookies, authentication tokens, and business application logins, then sends that data to criminal markets. The infection often happens on a personal or unmanaged device outside the corporate perimeter, so it does not trigger a security alert. In 2025, SpyCloud recaptured 642.4 million exposed credentials from 13.2 million infostealer infections, and 40% of those infections occurred on endpoints that already had EDR or antivirus tools installed, according to the 2026 SpyCloud Identity Exposure Report. Once that data is exposed, a trusted employee becomes an unwitting entry point an attacker can use to log in as them.

Remote IT worker fraud is a scheme in which an operative uses a stolen or fabricated identity, often supported by fake resumes and multiple personas, to get hired into a remote role and gain trusted access. North Korean, or DPRK, IT worker campaigns are the most prominent example and have become a board-level concern. Traditional background checks miss it because each submitted identity element can look legitimate in isolation. SpyCloud investigates from the criminal underground side instead, correlating the identity artifacts a candidate submits against recaptured breach, malware, and phishing data to expose connected personas, shared VPN infrastructure, geographic inconsistencies, and reused password patterns before access is granted. According to the SpyCloud 2025 Insider Threat Pulse Report, 87% of organizations already involve HR or recruiting in their insider threat defense, but about 60% still coordinate manually with no automated workflows.

At pre-hire screening, SpyCloud Cybercrime Investigations correlates a candidate’s identity against recaptured criminal underground data to surface fraudulent identities or adversarial infrastructure before an offer is extended. During employment, SpyCloud Workforce Threat Protection and Endpoint Threat Protection continuously monitor for compromise, and Identity Guardians resets exposed passwords and revokes active sessions through Active Directory, Microsoft Entra ID, or Okta Workforce. At offboarding, SpyCloud can confirm whether a departing employee’s access artifacts are circulating in criminal markets so revocation is targeted. Routing these signals into IdP, SOC, and HR workflows through the SpyCloud API closes the manual coordination gap that most insider threat programs still have.