How to Perform an Investigation on a Privileged User

1. Introduction

Users who have administrative privileges are the most important users within your organization, but they also represent the biggest risk to your data security.

Administrative rights are essential to the efficient running of any IT system as they enable trusted users to perform essential tasks like installing software, adding new accounts, creating passwords and the many other system modifications needed to do their job.

The flip side of this, however, is that admin rights provide the user with the ‘keys to the kingdom’ and therefore present a huge risk to the security of an organization’s data.

2. Privilege Abuse

When a user, either intentionally or accidentally, misuses legitimate privileges they have been granted it is known as privilege abuse. Despite these privileges being legitimately granted, users may access resources or perform actions that compromise data security.

Whether privilege abuse occurs through users purposefully mishandling data, or through employee carelessness, it is a security threat that must be taken seriously.

To be able to monitor any potential threat, it is essential for an organization to have complete visibility over the actions of their privileged users. But without a solution in place, tracking user activity can be a complex and time-consuming task.

3. Why Investigate a Privileged User?

The following scenario of a disgruntled employee is an example of why you might want to track a specific privileged user:

Jill is an administrator of a company and has worked there for just over 15 years. She has always been a very loyal and diligent employee and there has never been any cause to doubt her integrity.

Recently a new managerial job has been created within the company which Jill thinks she is perfect for. Because of her loyalty and hard work, she assumes she will get this position. She goes through the interview process thinking it’s just a formality and has her heart set on this new job with more responsibility but with a higher salary and other additional financial benefits.

But Jill does not get the job. A candidate from outside the company is selected and Jill is devastated.

Jill feels angry and resentful of her employers and decides she will resign rather than work for this new manager.

As Jill has admin privileges, she could potentially cause a lot of damage to the company and put their IT systems at a high level of risk. Without a solution in place, it would be almost impossible to track everything that Jill has done and so any malicious activity would go unnoticed until it caused a problem.

4. The Lepide Solution

The Lepide Data Security Platform offers a solution to this scenario. It has functionality to enable you to report on all activities for a particular user over a specified time-period and across all installed components.

In the scenario described in Section 3 above, the company can track all activity for Jill in the weeks leading up to her resignation. If there is any suspicious activity, it can be investigated, and then remedial action taken to mitigate risk and reduce any damage.

5. How to Track the Actions of a Privileged User

All user actions are tracked using the All Environment Changes Report

This is a holistic approach whereby all changes are reported across the different components including File Server, Active Directory and Microsoft 365.

5.1 Running the Report

Follow the steps below to run the All Environment Changes Report:

From the Web Console Home Page select Auditor:

Home Page
  • The Lepide Auditor reports are displayed:

Auditor Reports

  • From the tree structure on the left-hand side, click on All Environment Changes to display the All Environment Changes Report:

The All Environment Changes Report

5.1.1 Specify a Date Range

  • From the top of the screen, click the drop-down arrow next to the date to choose a date range for the report

The following dialog box is displayed:

Date Range Filter

  • Select a date range from the list and you will return to the All Environment Changes screen

5.1.2 Specify the User

  • To add a filter, click the Filter icon:

    Figure 5: Filter Options

  • The Modify Filters dialog box is displayed. Click the drop-down arrow next to Select and select which option to filter by:

'Who' Filter Selected
  • From the list of filter options, select Who

The following is displayed:

Editing ‘Who’ Filter

  • Click the Edit Filter icon:

    Add a Name to the 'Who' Filter

All Environment Changes Report with Filters

The Who Filter dialog box is displayed:

  • Type the name you want to filter by

  • Click Apply

  • Click Apply

  • Click Generate Report

In the example below, the report has been filtered on Lee.Russell:

The report shows all system activity for Lee between 6 – 12 June and includes some actions that require further investigation.

  • If we analyze the screenshot above, we can see a pattern of suspicious behavior:

    • A user has been deleted

    • Users have been enabled/disabled

    • A file has been read

    • File permission changes have been made

Now that there is visibility over the actions of this user, further investigation can take place.