Traffic
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade is an evidence-first detection and investigation platform for adversarial activity that becomes intentionally less observable.
Illustrative telemetry patterns grounded in supported ThreatFade scenarios. Not a live detection result.
A communication pattern becomes less observable over time.
ThreatFade is built around a specific detection thesis: adversarial activity can become less observable on purpose. The system models changes in network or signal behavior instead of treating a reduction in activity as automatically benign.
That produces an investigation path rather than a black-box verdict: prioritize the deviation, inspect structured evidence, pivot through context, disposition the case and hand off to existing security operations.
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade extracts observable signal features, including rolling entropy and statistical behavior.
Detection rules evaluate changes such as C2 quieting, LOTL fade and GNSS signal disruption.
Deviation and optional ML anomaly analysis help prioritize behavior that warrants inspection.
Structured evidence, confidence and context are preserved for analyst review.
Detections can carry MITRE ATT&CK context before operational handoff.
Results can move through JSON, Sigma-compatible, STIX 2.1-compatible and SIEM/FusionOps paths.
Start with the open-source engine, understand the detection surface and contribute against real implementation.
Open GitHubFollow the detection methodology, deterministic validation and research boundary without confusing project evidence with independent assurance.
Explore pathEvaluate evidence-backed detections, analyst workflow, ATT&CK context and operational interoperability.
Explore pathReview identity, tenancy, audit, deployment boundaries and the evidence-versus-assurance distinction.
Explore pathTests, benchmarks, controls and documented validation are inspectable in the source repository.
Published validation is explicitly scoped; it is not presented as a universal accuracy guarantee.
Certifications, independent testing, contractual SLAs and customer-scale guarantees require separate evidence.
The engine repository contains the detection engine, API, analyst console, validation framework and interoperability layer.