L1
L1 Analyst
SOC · New York
Triage QueueCASE-2026-0847
AdvisoryESCALATE92%

All three source systems independently observed exfiltration-shaped behavior on the same identity within 72 hours, with a file-fingerprint pivot from blocked USB to personal cloud. Destinations are exclusively personal/external. Employment is terminating. Confidence is high; FP likelihood is low.

Suggested next steps · one-click (advisory)
AI Triage (live)LIVE AI · Gemini Flash PII redacted
Click Generate to call the model. Streams in real time from Lovable AI. Citations like [E1] link to timeline events.
Incident Narrative (live)LIVE AI · Gemini Flash PII redacted
Click Generate to call the model. Streams in real time from Lovable AI. Citations like [E1] link to timeline events.
AI Audit Log0 entries
No AI calls recorded for this case yet. Triage, narrative, and chat calls will appear here automatically.
SLA Timer
11m remaining
Triage
2
Investigation
3
Resolution
JM

Bulk borrower-NPI egress by departing Loan Operations Analyst

ToolHighAICriticalΔIn Triage
James Mitchell · Senior Loan Operations Analyst · Mortgage Servicing
EMP-4471Mgr: Sarah O'BrienNew York, NYHours: 09:30–18:30 EST
Resigned — last working day in 4 days
94
Critical
7d trend
Collapsed from
DLP×6Proxy×4SIEM×4
Created2026-06-08 10:30 IST
Assigneeunassigned
MITRE T1078 · Valid AccountsMITRE T1530 · Data from Cloud StorageMITRE T1052 · Exfiltration / Physical MediumMITRE T1567.002 · Exfil to Cloud StorageMITRE T1537 · Transfer to Cloud AccountMITRE T1048 · Exfil / Alternative ProtocolMITRE T1213 · Data from Info Repositories

Correlation graph — why these are one caseThe pivots (identity, files, destinations, devices) that link every alert in this case. Click any node to drill into other cases that share it.

Open Correlation Explorer
Identity File Destination Device3 cross-case pivots touch this case
EMP-4471James MitchellServicing_Portfolio_Q2Account_Plans_Top50Onboarding sheet (email)USB SanDisk ****A91Cmega.nzPersonal Google Drivejames.personal@gmail.com
Click any node to inspect the pivot and other cases that share it.
Drill-down
Click a node in the graph to see its pivot details and any other cases it links to.

Unified incident timelineAll raw alerts in this case merged in chronological order. Click an item to expand the redacted evidence.

DLP Proxy SIEM
06 Jun 2026
07 Jun 2026
08 Jun 2026

AI triage assist · advisoryAI-drafted summary, kill-chain, FP likelihood and citations. Always advisory — analyst must validate before acting.

Case summary

Departing Sr. Loan Operations Analyst (EMP-4471, last day in 4) shows a 72-hour pattern consistent with intentional borrower-NPI exfiltration across endpoint, web, and email. The pivot is a single file (Servicing_Portfolio_Q2) blocked on USB, then successfully uploaded to personal Google Drive within 2 hours — corroborated by 740 MB to mega.nz, a quarantined NPI email to a personal account, and a 9,200-record servicing-portfolio export.

MITRE kill-chain
  1. 1.Initial AccessOff-hours VPN from first-seen residential IP (T1078).
  2. 2.Collection287-file bulk read of borrower repository; 9,200-row servicing export.
  3. 3.StagingServicing_Portfolio_Q2 prepared on endpoint; USB copy attempted.
  4. 4.ExfiltrationPersonal Google Drive (fingerprint match), mega.nz 740 MB, quarantined email to personal Gmail.
False-positive likelihood
6%
RAG citations
  • SOP-IR-014 — Insider Threat / Departing Employee Triage §3.2 mandatory escalation
  • Altisource GLBA Safeguards Policy §5 NPI handling on personal devices
  • Forcepoint DLP Policy NPI-SSN-Block rev 2026.04
Similar past cases
  • CASE-2025-9112Departing analyst — NPI to personal Drive (Escalated)
  • CASE-2025-8730USB copy → mega.nz pattern, Mortgage Ops

Analyst notes (0)Free-text observations added by analysts during triage. Visible to L2 on escalation.

No notes yet — add your first observation below.

Case audit timelineImmutable log of every action on this case — analyst, AI, and integrations. Used for compliance review.

2026-06-08 10:30 ISTingestAlerts ingested14 alerts (DLP 6, PROXY 4, QRADAR 4)
2026-06-08 10:30 ISTredactorPII redaction appliedSSN, loan numbers masked
2026-06-08 10:30 ISTenricherIdentity + HR context enriched
2026-06-08 10:30 ISTai-triageCorrelated 14 → 1 caseshared identity + fingerprint + 72h burst
2026-06-08 10:30 ISTai-triageAdvisory: ESCALATE (92%)
AI output is advisory. QRadar SIEM, Forcepoint DLP, and Forcepoint Proxy remain authoritative source systems. Sensitive values (SSN, account/loan numbers) are redacted before AI processing.