Interesting approach
http://findingbad.blogspot.com/2021/02/more-behavioral-hunting-and-insider.html
MITRE's engenuity insider threat knowledgebase
https://ctid.mitre-engenuity.org/our-work/insider-ttp-kb/