TFTHREATFADE
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
GitHub
ProductDetectionHow it worksIntegrationsResearchSecurityDocsPlaygroundPricingEnterprise
HomeDetection

Detect behavioral fade, not just loud indicators.

ThreatFade's current detection baseline combines rolling Shannon entropy, z-score anomaly detection, detection rules, confidence scoring and an optional Isolation Forest layer.

Behavioral signal lab

Illustrative telemetry patterns grounded in supported ThreatFade scenarios. Not a live detection result.

Research surface
baseline / observable activitybehavioral change
Signal interpretation

A communication pattern becomes less observable over time.

Observed change
signal reduction
Scenario family
C2
Next step
Inspect evidence
Detection → evidence → disposition

Current detection pipeline

01

Traffic

PCAP, live signals and supported telemetry sources enter the detection boundary.

02

Signal extraction

ThreatFade extracts observable signal features, including rolling entropy and statistical behavior.

03

Behavioral analysis

Detection rules evaluate changes such as C2 quieting, LOTL fade and GNSS signal disruption.

04

Anomaly

Deviation and optional ML anomaly analysis help prioritize behavior that warrants inspection.

05

Evidence

Structured evidence, confidence and context are preserved for analyst review.

06

ATT&CK

Detections can carry MITRE ATT&CK context before operational handoff.

07

Integration

Results can move through JSON, Sigma-compatible, STIX 2.1-compatible and SIEM/FusionOps paths.

C2

C2 quieting scenarios and detection rule TF-C2-001.

LOTL

Gradual living-off-the-land activity reduction and TF-LOTL-001.

GNSS

Signal disruption scenarios and TF-GNSS-001.

THREATFADE / TINLANCE LIMITEDSource on GitHub