ThreatFade models deliberate reductions in observable adversarial behavior, scores the deviation and preserves the evidence analysts need to investigate it.
Rolling Shannon entropy, statistical deviation, detection rules and an optional ML anomaly layer form the current detection baseline.
Detection records preserve structured evidence, confidence and context for analyst review and disposition.
The engine includes an analyst console and operational paths designed to complement existing security operations.
The repository contains the detection engine, API, dashboard, validation framework and interoperability layer.
Start with the open-source engine, understand the detection surface and contribute against real implementation.
Open GitHubFollow the detection methodology, deterministic validation and research boundary without confusing project evidence with independent assurance.
Explore pathEvaluate evidence-backed detections, analyst workflow, ATT&CK context and operational interoperability.
Explore pathReview identity, tenancy, audit, deployment boundaries and the evidence-versus-assurance distinction.
Explore path