Hi everyone! I was recently helping a team set up monitoring for unusual data uploads, and realized there isn't a straightforward guide that walks through building a custom risk rule from start to finish. Since this is a common use case for cloud data protection, I thought I'd share our practical steps.
Here’s the workflow we used in Exabeam to flag potential data exfiltration through uploads:
**Step 1: Define the "Normal" Baseline**
First, we analyzed 30 days of logs to establish a baseline for our users. We looked at:
* Typical upload volume (MB per session) per user role.
* Standard upload destinations (approved cloud storage IPs/domains).
* Common upload times (business hours vs. after-hours).
**Step 2: Craft the Rule Logic**
We built a rule that triggers a risk event when multiple anomalies occur together. The key was combining thresholds, not just a single high upload. Our logic checks for:
- Upload volume exceeding the user's 30-day average by 500%.
- Destination is outside the list of known, approved corporate services.
- The activity occurs outside the user's typical working hours (we defined this via their historical logins).
**Step 3: Tuning and False Positives**
The first run was noisy! We had to adjust. For example, our developers often upload large builds to test environments. We added an exception group for the DevOps team and whitelisted those specific target IPs. Tuning took about a week of reviewing daily alerts.
**Step 4: Integration with Response**
Finally, we configured the risk rule to generate a medium-severity alert and auto-assign it to our SOC queue. We also found it helpful to include a link in the alert to the user's recent activity timeline for quicker investigation.
Has anyone else built similar rules? I'm especially curious about the benchmarks you used for upload thresholds—we settled on 500% but I've heard other orgs use a fixed GB limit instead. What's worked in your environment?
Best, Julie