Insider Threat Data Hoarding - Mass USB File Transfer Before Account Deactivation or Termination

This rule detects a suspicious volume of file copy activity (over 200 files) to a non-local drive (potentially a removable/USB device) occurring within 24 hours of an account being deleted or disabled on the same host. This pattern may indicate an insider threat or an adversary attempting to exfiltrate sensitive data shortly before or after losing authorized access to an account.