Traffic
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade's operational loop is designed around evidence: prioritize, inspect, pivot, disposition, then hand off to the systems that already run security operations.
PCAP, live signals and supported telemetry sources enter the detection boundary.
ThreatFade extracts observable signal features, including rolling entropy and statistical behavior.
Detection rules evaluate changes such as C2 quieting, LOTL fade and GNSS signal disruption.
Deviation and optional ML anomaly analysis help prioritize behavior that warrants inspection.
Structured evidence, confidence and context are preserved for analyst review.
Detections can carry MITRE ATT&CK context before operational handoff.
Results can move through JSON, Sigma-compatible, STIX 2.1-compatible and SIEM/FusionOps paths.
Use detection evidence, confidence and context to decide what deserves attention.
Open the structured detection record and examine the observable evidence behind it.
Use ATT&CK context, signal details and operational metadata to investigate the event.
Record the analyst outcome rather than treating the detector as the final authority.
Export or integrate the result into existing security operations workflows.
The repository separates the control plane from detection workloads and provides tenant-scoped persistence, audit events, an analyst console and interoperability paths. Production authentication is fail-closed and deployment-specific identity configuration remains an operational requirement.