DTEX Insider Risk Management helps enterprise security teams identify signs of insider-driven breaches by combining user activity monitoring with behavioral context and visibility into interactions with data and AI. Preconfigured or customizable indicators, user baselines, anomaly detection, and risk scores help surface activity for review. Investigations can use MITRE ATT&CK-aligned profiling and endpoint details such as event logs, registry changes, and credential usage to examine signs including lateral movement and privilege escalation. Preconfigured DLP patterns flag risky behavior, while data lineage tracks file interactions and changes. A threat-hunting engine supports searches across insider data with an open query language and customizable visualizations. The platform covers users, endpoints, servers, applications, data, and AI activity. DTEX says lightweight forwarders collect 3–5 MB per user per day, continuously and on or off network. Pseudonymization masks personal identifiers, with reversal available for escalated investigations. It runs on Linux, macOS, Windows, and the web. Pricing is available on request.
Who it is for
It is presented for enterprise security teams investigating risks such as privilege misuse, shadow AI, leavers and joiners, and state-sponsored insider threats. Organizations seeking investigative support can also use DTEX i³ services.
What is good
- Behavior indicators, baselines, anomaly detection, and risk scoring
- MITRE ATT&CK-aligned profiling and endpoint telemetry
- Data lineage and preconfigured DLP patterns
- Pseudonymization can be reversed for escalated investigations
- Integrates with security, productivity, HR, and data platforms
What to know first
- Pricing is available only on request
- Collection is described as 3–5 MB per user per day
Verdict
DTEX combines behavior analytics, investigation telemetry, data-loss visibility, and threat hunting for insider-risk work. Its pricing requires a request, and its privacy approach includes pseudonymization that can be reversed for escalated investigations.
DTEX Insider Risk Management plans and pricing
All plansCompared on insider risk management software
- Entity coverage
- users, endpoints, servers, applications, data, AI activity
- Anomaly methods
- ml_based
- Response automation
- automated



