A research-oriented organization engaged DTEX i3 Services to strengthen its ability to identify and assess insider risk. Proactive threat hunting surfaced an employee researching multiple routes to higher-risk foreign destinations. A deeper person-of-interest (POI) investigation then examined related alerts and other correlated risky behaviors. The activity did not establish malicious intent or a policy violation, but the added context gave the organization an opportunity to verify compliance with travel-notification requirements and reinforce those requirements with its broader workforce.
Company profile
The customer is a research-oriented organization operating in a security-sensitive environment. Its workforce includes employees with security clearance and travel-reporting obligations, making timely awareness of potential compliance concerns important to the organization’s broader insider risk program.
The need: finding risk signals without jumping to conclusions
Foreign travel can create security and compliance considerations for organizations whose employees hold clearances or work with sensitive information. The challenge is not simply identifying a destination. Security teams need enough context to determine whether activity should be reviewed, while avoiding assumptions based on nationality, personal ties, or legitimate travel planning.
The organization was working to improve analyst familiarity, triage, and use-case understanding. DTEX needed to demonstrate how expert-led hunting and deeper POI investigation could turn behavioral activity into a focused, proportionate assessment.
The incident risk
Through proactive threat hunting, an i3 analyst identified an employee researching international travel to a sanctioned country. DTEX telemetry showed the employee researching and booking travel, comparing flights and routes through sanctioned countries, and exploring potential onward rail connections. The activity continued as recently as the day before the analyst’s report.
Open-source intelligence (OSINT) was used only to validate and add context to the activity observed in DTEX telemetry. Publicly available professional information confirmed the employee’s engineering-related role and an education history in a sanctioned country that aligned with the intended destination. The employee’s established tenure and personal ties provided plausible context for legitimate travel. None of these factors, on their own, established wrongdoing.
The solution: DTEX i3 services
DTEX i3 analysts supported the organization through training, triage, platform familiarization, and proactive threat hunting. After the initial behavior surfaced, the analyst conducted a deeper POI investigation across alerted and other correlated risky behaviors. Rather than treating the travel activity as proof of malicious intent, the analyst combined observed behavior with relevant context and delivered an assessment designed to support informed customer action.
All travel-related activity, including research, bookings, flights, routes, and countries, came directly from DTEX telemetry. OSINT was used only to confirm the employee’s role and education history and to provide additional context. This distinction helped the organization understand what had been observed, what the supporting context showed, and why the matter warranted verification through its established internal process.
What DTEX i3 observed through telemetry:
- Research and booking activity for flights from the employee’s home country to destination in a sanctioned country
- Comparison of alternative routes through sanctioned countries, including flights and possible onward rail connections
- Review of travel options through sanctioned countries
- Travel-planning activity that remained active close to the time of reporting
- Correlated alerts and other risky behaviors reviewed as part of the deeper POI investigation
- OSINT validation of the employee’s role and education history, used only to add context to the telemetry findings
The response
The i3 team escalated the finding for organizational awareness and recommended confirming whether the employee had complied with applicable travel-notification, security, or approval requirements. The organization initiated an internal investigation and re-emphasized the need for cleared personnel to register relevant travel through the required reporting process.
Because the investigation remained ongoing, the organization did not treat the activity as a confirmed violation. The response centered on awareness, verification, and consistent application of policy.
The results
The assessment gave the organization earlier awareness of planned travel to higher-risk jurisdictions, enabled by timely escalation, and prompted it to reinforce applicable travel-reporting requirements across the broader workforce.
More broadly, additional training, triage, familiarization, and expert-led threat hunting helped the customer recognize greater value from the engagement. The results moved beyond platform access alone and showed how experienced analysts can help translate behavioral activity into defensible decisions.
Benefits
- Earlier awareness: Surfaced ongoing travel research and booking activity in time for the organization to review applicable reporting obligations.
- Evidence-led escalation: Combined telemetry with supporting OSINT context without labeling legitimate personal activity as malicious.
- Clearer escalation and remediation path: Demonstrated how proactive threat hunting and deeper POI investigation can uncover activity that requires human judgement and organizational context.
- Stronger security awareness: Prompted the organization to reinforce travel-reporting expectations across its broader workforce.
Why this approach matters
Effective insider risk programs do not reduce risk to a single alert, identity attribute, or destination. They bring together behavioral evidence, human expertise, organizational policy, and proportionate response. In this case, the most valuable outcome was not a declaration of wrongdoing. It was the ability to identify activity that warranted review, add context, and route the matter through the right process. The same principle applies to travel involving adversarial, sanctioned, or otherwise higher-risk jurisdictions.
Lessons learned and best practices
- Define travel-reporting requirements clearly, including expectations for adversarial, sanctioned, or otherwise higher-risk jurisdictions.
- Use observed behavior as a starting point for assessment, not a substitute for investigation.
- Separate telemetry-based observations from OSINT used to validate or add context.
- Escalate proportionately and preserve legitimate explanations until facts are established.
- Pair technology with analyst training, triage support, proactive threat hunting, and use-case familiarization.
The bottom line
DTEX i3 Services helped a research organization turn an ambiguous behavioral signal into a focused, defensible assessment. By combining proactive threat hunting, a deeper POI investigation, and careful contextual analysis, the i3 team enabled earlier awareness, faster escalation, and verification of travel-reporting requirements without presuming malicious intent.
Speak with the DTEX i³ Team
Learn how DTEX i³ Services can help your organization identify, investigate, and respond to insider risk with expert-led intelligence and investigations.





