TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
HomeProduct

An evidence-first detection and investigation platform.

ThreatFade models deliberate reductions in observable adversarial behavior, scores the deviation and preserves the evidence analysts need to investigate it.

Detection

Behavioral change is the object of analysis.

Rolling Shannon entropy, statistical deviation, detection rules and an optional ML anomaly layer form the current detection baseline.

Evidence

A detection should leave an inspection trail.

Detection records preserve structured evidence, confidence and context for analyst review and disposition.

Workflow

Prioritize → Inspect → Pivot → Disposition → Handoff.

The engine includes an analyst console and operational paths designed to complement existing security operations.

Open source

The implementation is part of the product surface.

The repository contains the detection engine, API, dashboard, validation framework and interoperability layer.

Choose your evaluation path

Run / inspect / contribute

Developers

Start with the open-source engine, understand the detection surface and contribute against real implementation.

Open GitHub
Methodology / evidence

Researchers

Follow the detection methodology, deterministic validation and research boundary without confusing project evidence with independent assurance.

Explore path
Detect / investigate / handoff

SOC teams

Evaluate evidence-backed detections, analyst workflow, ATT&CK context and operational interoperability.

Explore path
Architecture / security

Enterprise

Review identity, tenancy, audit, deployment boundaries and the evidence-versus-assurance distinction.

Explore path
THREATFADE / TINLANCE LIMITEDSource on GitHub