Salesforce interview question

How would you approach identifying malicious user behavior?