Jun 26, 2026

Roger Goes Rogue: Detect Privileged Misuse Before Exfiltration

5

How to detect data theft intent before exfiltration

Meet Roger. Again. 

Only this time, he’s not renaming files or playing zip-and-encrypt games. He doesn’t have to. Roger has something better: privileged access, a remote job, and an AI agent that can do the digging for him.

On paper, he looks exactly like the kind of hire every organization makes. He’s a new remote IT systems admin. He’s smart, trusted, and granted high-level access to servers that run the business. He works normal hours, uses legitimate tools, and doesn’t come crashing through the front door waving red flags. That’s what makes this version of Roger more dangerous.

In part three of our “Meet Roger” series, Roger is still a character, but he’s also a pattern. Sometimes he’s a careless employee, or he’s a contractor with too much access. Other times he’s a compromised account. In the story, he’s the employee sitting in a privileged seat with every reason to look legitimate and every opportunity to do damage before security teams realize what’s happening.

Watch how Roger’s actions progress, and how DTEX controls adapt in real-time. 👇

Chapter three of the “Meet Roger” series: Roger Goes Rogue

When privileged access looks normal

Privileged misuse is difficult to catch for a simple reason: privileged users are supposed to do sensitive things. Admins touch servers. They access repositories. They use tools other employees never see. A lot of that activity is completely normal, until it isn’t.

That’s exactly what happens here. Roger isn’t manually searching through systems or moving files one by one. He delegates the work to an AI agent. The agent maps where sensitive AI engineering project data lives, stages it for transfer, and queues it up at machine speed. All Roger has to do is approve it.

That detail matters. A lot. Because AI changes the shape of insider risk. It doesn’t invent privileged misuse, but it makes it faster, quieter, and easier to scale. The work still appears to come from a legitimate user with legitimate access. It just moves a lot faster than security teams are used to seeing.

Why traditional controls miss the story

This is where static thinking falls apart.

Traditional controls are usually waiting for a single obvious violation. A known transfer path. A policy match. A final move that clearly breaks the rules. But most real incidents don’t start that way. They start as routine work that quietly shifts into risk. That was the point of chapter two in this series. The difference now is that Roger has elevated privileges, server access, and AI helping him move faster.

By the time a traditional control sees the final transfer, the story is already well underway. The sensitive repository was already accessed. The files were already staged. The behavior had already changed. Roger had already shown intent, even if the system wasn’t built to recognize it.

That’s why privileged misuse is such a problem for modern security teams. It rarely announces itself with one dramatic action. It builds through a sequence of small, explainable moves: a new tool, unusual volume, access that feels a little off, automation that shouldn’t be there, and a business justification that doesn’t line up with the surrounding behavior. On their own, those signals may look ordinary. Together, they tell a very different story.

And that story matters. According to Ponemon’s 2026 Cost of Insider Risks Global Report, 92% of organizations say generative AI has changed how employees access and share information, while 73% worry unauthorized AI use is creating invisible paths for data exfiltration. Roger works because he sits right in the middle of that reality: trusted access, normal-looking behavior, and risk that builds faster than most teams can see.

What it looks like to catch intent early

The goal isn’t to block everything a privileged user does. The goal is to recognize when normal work stops being normal.

In this chapter, that means seeing the build-up before the data leaves the server. Roger accesses a sensitive engineering repository. He uses an unsanctioned AI agent. He stages a large volume of data for automated transfer. The activity looks increasingly out of step with what should be happening for this role. As risk rises, DTEX controls tighten automatically. The transfer is paused, and Roger is prompted to provide a business justification. When that justification doesn’t match the surrounding behavior, enforcement escalates. DTEX quarantines the user before the sensitive engineering data transfer is complete, helping to contain the risk.

Roger goes rogue

That’s the real shift. Instead of waiting for the final event, security can respond to the trajectory. Instead of treating every action as isolated, teams can understand the pattern. Instead of forcing analysts to piece together what happened after the fact, they can see the intent forming in real time.

How DTEX helps

This is where the DTEX Platform matters.

As Roger’s risk changes, DTEX keeps the thread together. It continuously monitors server activity for behavioral shifts, including automated data transfers and unsanctioned admin tool usage. It adapts automatically as Roger’s risk changes, instead of relying on static rules that only fire after the fact.

For security teams, the DTEX Control Center separates insider risk profiles from data loss prevention (DLP) events so analysts can examine risky users with the right context instead of sorting through disconnected alerts. And when incidents need to move quickly, DTEX Risk Assistant, part of the DTEX Agentic Defender suite, can summarize activity and recommend next steps, helping teams understand what happened without recreating the full chain by hand.

The DTEX Control Center

For organizations where the stakes are even higher, DTEX i3 extends security teams with expert hunting, intelligence, and evidence-based investigations to bring deeper context and faster resolution when organizations need it most.

Roger isn’t always Roger

Roger can be any insider: an employee, a contractor, or a compromised account with privileged access and the intent to misuse it. That’s what makes him useful as a story device, and uncomfortable as a security reality.

Almost every organization has some version of Roger somewhere in its environment. The question is whether your team can see the difference between normal privileged work and the quiet build-up to data theft before it becomes a breach.

Watch the next chapter in the “Meet Roger” series to see how the DTEX helps stop malicious insiders early and provides the behavioral context behind the risk that matters.

FAQ: managing AI insider risk

Privileged misuse happens when someone with elevated access uses that access in a way that creates security, operational, or data protection risk. That can involve a malicious insider, a contractor, or a compromised account operating through legitimate privileges.

You detect it by looking at the sequence of behaviors before the final transfer, not just the transfer itself. In Roger’s case, those signals include sensitive repository access, unsanctioned AI agent usage, automated staging, unusual transfer behavior, and a justification that doesn’t match the context.

Because privileged users often perform sensitive actions as part of their normal work. Without behavioral context, many tools struggle to separate legitimate admin activity from misuse, compromise, or intent.

AI can accelerate insider risk by helping users automate reconnaissance, data staging, and transfers at machine speed while still acting through legitimate access. That makes risky behavior harder to distinguish from normal work unless teams can see the broader pattern.

Subscribe today to stay informed and get regular updates from DTEX