Findings

Accelerate your alert workflow with Findings.

Accelerate your alert workflow with Findings.

Findings provide your analysts with pre-triaged alerts, evidence, the ability to investigate quickly and to respond even faster.

Search...⌘K
Home
Detections
Findings
Reports
Timeline
Identities
Recent inquiries
Environment Investigation Complete...
Identifying Non IdP Managed Accounts
Getting started with Icite
VPN Usage Status Unknown
ISP Usage Last Five Days
View all
Shared with you
Agentic AI Activity Overview
Claude Code identities and delegat...
High Risk Users MFA Admin Access
Icite Throxy Employee Interaction...
Kevin Manson Application Access...
Finish onboarding 3/6
Icite
ty@icite.io
FindingsDeparting actor — multi-platform exfil (toxic combination)

Departing actor — multi-platform exfil (toxic combination)

This detection flags a single toxic-combination condition — one departing actor moving sensitive data across multiple platforms (Salesforce report exports, GitHub repo clones, Google Drive access changes) in the run-up to their termination. One entity is flagged: Sarah Chen (Senior Sales Engineer, Sales, pending_termination), whose activity spans five linked platforms and whose recent data-movement events cluster on off-corporate IPs in the Naperville range. This is a standing roster that shifts as accounts match or clear the detection; on this first triage there is no movement yet — Sarah Chen has been the sole member since the finding opened.

Triage snapshot · July 24th, 2026 1:00 AM MDT
Things we found
Recommendations
Triage
Investigation

Overview  The data confirms that sarah.chen@lumon.industries is a single canonical identity resolved across Entra, Salesforce, GitHub (sarahc-lumon), Google Workspace, and Workday, and that her Workday record shows employment status pending_termination with a termination date of 2026-07-28. In the 7/21–7/23 window we observed a converging pattern of data-movement activity across platforms: repeated Salesforce Report Export events, GitHub git.clone events against lumon/sales-data-export, lumon/quote-engine, and lumon/billing-service, and a sustained run of Google Drive access-change events on sales files (Customer Master, Top 200 accounts contacts, Net-new pipeline, Renewal forecast). A notable split in origin: business-hours activity comes from Chicago IPs (198.51.100.x), while the late-night data-movement events run from a Naperville range (203.0.113.x). The surfacing evidence cites a sales-data-export clone tied to Salesforce report 00OLmn00000Cust at 2026-07-23 22:34Z; at that same minute we see an Entra sign-in to Salesforce and a Salesforce Report Export from the Naperville range. What the data cannot confirm: whether any exported/cloned data left approved boundaries (no DLP or egress/upload telemetry is visible here), whether the two IP ranges correspond to her managed device or personal infrastructure, and whether these actions exceed her legitimate role — her account holds the Salesforce "Export Reports" role and GitHub write on billing-service as baseline, but the clones of quote-engine and sales-data-export fall outside confirmed baseline access. The account remains enabled and un-isolated across all five platforms as of this triage.

Supporting facts
  • Identity resolves across 5 platforms (Entra, Salesforce 005Lmn00000Chen, GitHub sarahc-lumon, Google Workspace, Workday empl-lumon-00042); Workday status pending_termination, termination date 2026-07-28; manager Helena Cole. Source: identity profile.
  • Account state: all source accounts enabled/active, MFA enrolled, isIsolated = false. Source: identity profile.
  • GitHub clones in-window: lumon/sales-data-export (7/21 20:55Z, Naperville), lumon/quote-engine (7/22 13:28Z Chicago; 7/23 13:05Z and 14:09Z Chicago), lumon/billing-service (7/22 21:17Z, Naperville). Baseline GitHub access is write on billing-service only.
  • Salesforce Report Export events cluster on 7/22 evening (21:05–21:33Z, Naperville) and 7/23 22:34Z (Naperville); baseline includes the "Export Reports" role.
  • Google Drive access-change events on ~10+ sensitive sales files across 7/21–7/23, predominantly from the Naperville 203.0.113.x range during late-night hours.
  • Origin split: business-hours Chicago (198.51.100.x) vs. late-night Naperville (203.0.113.x). Google recovery email on file is a personal address.
Next steps
  • Confirm whether the Naperville 203.0.113.x sessions originated from Sarah Chen's managed device or unmanaged/personal infrastructure — pull device/session context for those sign-ins.
  • Pull the full Salesforce Report Export detail (report 00OLmn00000Cust / target 00OLmn00000Cust) to confirm which records/objects were exported and their volume, since export payload is not visible in current data.
  • Given the account is enabled and un-isolated with a termination date of 2026-07-28, confirm the intended offboarding/containment timing with the account owner (manager Helena Cole) against the observed cross-platform data-movement.
Sources: identity_get_user_details, timeline_query_events
Ask follow up
Re-run triage
Close finding
Details
SeverityHigh
StatusActive
Members to classify1 of 1
Opened onJuly 24th, 2026 1:00:02 AM MDT
DetectionDeparting actor — multi-platform exfil (toxic c…
MITRE TacticsTA0010
MITRE TechniquesT1530T1213
IDfnd-s7f9n9rsyl5m
Follow up inquiry
Ask about Departing actor — multi-platform exfil (toxic combination)
Start an investigation by asking follow up questions and have the agent add context to the triage page.
Ask a follow up question…

Features

Features

The lifecycle

From signal to closed.

From signal to closed.

We run every finding through a series of automated steps. Gathering evidence, auto-triaging and defining threads that analysts can pull on to quickly remediate threats.

01
02
03
04
05
01
Detection fires
As soon as the detection fires, a finding is created with the implicated identities, severity and MITRE mappings

What's in a finding

Everything your analyst needs. Nothing they have to hunt for.

Everything your analyst needs. Nothing they have to hunt for.

Triage

Orient your analysts before they even start

Icite dispatches agents to summarize what the detection found, add evidence from your data, and — critically — state what wasn't assessed. Your analysts review a case file, not a query result.

"The three Conditional Access policies that target 'All users' are not enforcing — one is disabled and two are report-only…"

Members & classifications

Improve fidelity of findings and detections

Each finding lists its members — the identities implicated — with recurrence and first/last seen. Classification is one click, and every verdict feeds detection tuning. False positives make the system smarter, not just quieter.

False positive

True positive

Benign

Members

Member

Recurrence

First seen

Last seen

Classify

Emily Chen

Open

May 5th, 03:03:03

May 6th, 03:03:03

Emily Chen

Open

May 5th, 03:03:03

May 6th, 03:03:03

Emily Grace

Open

May 5th, 03:03:03

May 6th, 03:03:03

Randall Savage

Lapsed

May 3rd , 08:22:11

May 3rd , 08:22:11

Recommendations

The next three moves, ranked and specific.

Clear, actionable suggestions for analysts like: revoke the 247 external Drive shares, transfer ownership of the Customer Master List, remove the Salesforce export permission. Named resources, named identities, real blast-radius numbers.

Recommendations

01

Revoke external Drive shares

Revoke the 247 external shares on files owned by Emily Grace. These shares persist after termination and grant ongoing access to customer data unless manually expired.

02

Transfer ownership of the Customer Master List

Reassign ownership of the Customer Master List shared drive to her manager. Emily currently holds sole ownership, and no DLP rule is configured to flag further bulk exports from this drive.

03

Remove Salesforce export permission

Remove the "Export Reports" permission from Emily Grace's Salesforce profile. She triggered a 4 GB report export yesterday and retains the ability to repeat it until termination.

03

Revoke GitHub write to billing-service

Downgrade Emily Grace's access on billing-service from write to read-only. She recently pulled ‘customer_export.py’ from this repo, and write access lets her push or rewrite history before departure.

Investigations

Get the evidence you need, fast.

Start an investigation right from the finding. "Who else accessed that drive?" becomes an inquiry against the same correlated data — no pivot to the SIEM, no query language, no losing the thread. List out actual events, see configuration change diffs and add them right to the finding.

Measure what matters

Increase your analysts confidence and decrease your MTTR

Increase your analysts confidence and decrease your MTTR

Evidence based investigations right from the finding increases analysts confidence to respond.

Verified remediation —"fixed" is checked against subsequent detection runs, and lapses reopen the conversation.

Crush triage time with agent-written overviews the minute a finding is created. Analysts start with context not queries.

Feedback loop to detections — false-positive rates fall because classifications feed detection tune capabilities.

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc

Try it out

Start detecting identity threats today.

Built in the USA

Copyright© 2026, Icite Inc