Traffic
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade's current detection baseline combines rolling Shannon entropy, z-score anomaly detection, detection rules, confidence scoring and an optional Isolation Forest layer.
Illustrative telemetry patterns grounded in supported ThreatFade scenarios. Not a live detection result.
A communication pattern becomes less observable over time.
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade extracts observable signal features, including rolling entropy and statistical behavior.
Detection rules evaluate changes such as C2 quieting, LOTL fade and GNSS signal disruption.
Deviation and optional ML anomaly analysis help prioritize behavior that warrants inspection.
Structured evidence, confidence and context are preserved for analyst review.
Detections can carry MITRE ATT&CK context before operational handoff.
Results can move through JSON, Sigma-compatible, STIX 2.1-compatible and SIEM/FusionOps paths.
C2 quieting scenarios and detection rule TF-C2-001.
Gradual living-off-the-land activity reduction and TF-LOTL-001.
Signal disruption scenarios and TF-GNSS-001.