A real insider-threat case at Exabeam shows how a malicious hire aligned with DPRK interests evaded screening but revealed subtle anomalies over time. By combining telemetry, UEBA context, and AI-driven reasoning, weak signals formed a clear threat. This session will share what worked, what didn’t, and how to operationalize modern insider threat detection.