Insider threats pose a significant challenge to organizations, as malicious activities often mimic legitimate user behavior and bypass traditional security mechanisms. This paper presents a novel hybrid framework for insider threat detection based on anomalous user behavior analysis using multi-source log data. Detection of insider threats is a significant concern in the realm of cybersecurity. Insiders pose the greatest threat due to their unique access. Insider risks can be identified by the atypical activity of a user. The individual is engaged at his place of employment. All user activity on the device is recorded. The recorded data is utilized to analyze user behaviour and identify unusual activities. The user's log, device, and file data were curated, sanitized, and standardized in this study. Features are derived from insider log data. The statistical analysis has been conducted to determine the central tendency and dispersion of the data. It facilitated the classification of normative and abnormal user activity. The interrelationship between the user and the PC is depicted in an undirected bipartite graph. Anomalous user behaviour is analyzed for insider risks based on data. Significant risk mitigation measures may be implemented when the user is identified as a potential insider threat. A medium risk rating is established when the user is identified as anomalous in 50 percent of insider threat activities. Low-level risk measures are implemented against the user upon a determination of guilt in 25 percent of potential risk activities. The measures used against the user include warnings, penalties, account suspension, termination, and reporting to management for additional action on the insider danger about their risk level.