TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
HomeHow it works

A quiet channel becomes a measurable event.

ThreatFade's operational loop is designed around evidence: prioritize, inspect, pivot, disposition, then hand off to the systems that already run security operations.

01

Traffic

PCAP, live signals and supported telemetry sources enter the detection boundary.

02

Signal extraction

ThreatFade extracts observable signal features, including rolling entropy and statistical behavior.

03

Behavioral analysis

Detection rules evaluate changes such as C2 quieting, LOTL fade and GNSS signal disruption.

04

Anomaly

Deviation and optional ML anomaly analysis help prioritize behavior that warrants inspection.

05

Evidence

Structured evidence, confidence and context are preserved for analyst review.

06

ATT&CK

Detections can carry MITRE ATT&CK context before operational handoff.

07

Integration

Results can move through JSON, Sigma-compatible, STIX 2.1-compatible and SIEM/FusionOps paths.

01

Prioritize

Use detection evidence, confidence and context to decide what deserves attention.

02

Inspect

Open the structured detection record and examine the observable evidence behind it.

03

Pivot

Use ATT&CK context, signal details and operational metadata to investigate the event.

04

Disposition

Record the analyst outcome rather than treating the detector as the final authority.

05

Handoff

Export or integrate the result into existing security operations workflows.

Architecture boundary

The repository separates the control plane from detection workloads and provides tenant-scoped persistence, audit events, an analyst console and interoperability paths. Production authentication is fail-closed and deployment-specific identity configuration remains an operational requirement.

THREATFADE / TINLANCE LIMITEDSource on GitHub