Workday sensitive custom report generated

Cette page n'est pas encore disponible en français, sa traduction est en cours.
Si vous avez des questions ou des retours sur notre projet de traduction actuel, n'hésitez pas à nous contacter.

Goal

Detect users generating Workday reports that include sensitive data, which may indicate reconnaissance activity or potential data exfiltration attempts.

Technical Context

Workday is a Human Resources Information System containing sensitive employee and organizational data. This rule monitors the execution of custom reports to identify users who access data related to payments, elections, or a large export of employee records. Such behavior could indicate attackers using stolen credentials to systematically gather intelligence on employees.

Triage and Response

  1. Check if the user has a legitimate business role requiring access to multiple reports (such as HR analysts, auditors, or managers during review cycles).
  2. Review the specific reports accessed to understand the scope and sensitivity of data involved. Look for patterns that suggest systematic data collection.
  3. Examine the IP addresses, user agents, and timing patterns for signs of automated or suspicious access patterns.
  4. Compare this activity to the user’s historical report generation patterns to identify deviations from normal behavior.
  5. Look for correlated suspicious activity across other data sources for the same user, including unusual file downloads, database queries, or email patterns.
  6. For users in legitimate roles, reach out to their manager or the HR and payroll team to validate whether bulk report generation aligns with current business activities (such as performance reviews, audits, or compliance reporting).
  7. If the activity cannot be justified by legitimate business needs or shows signs of malicious intent, declare an incident.