insider-intel

REAL INSIDER CASES — WHAT ACTUALLY REACHES COURT

LIVE
Refine INSIDER FOCUS · ALL CHANNELS
Top Insider Risks
Scope
Min. Insider Confidence — SIG ≥ 30
Channel
Insider type

Connecting…

Latest

    Workbench

    The Workbench collects cases you flag with + FLAG from the stream. MODUS OPERANDI assembles them into a forensic case study — what each insider actually did, from stored court/report forensics. Use ⋯ to share, export, or import a board.

    The Workbench

    Flag cases from the stream with + FLAG and they land on the evidence board here. MODUS OPERANDI then shows the ITM techniques those insiders used, with per-case evidence and the traces each behavior leaves. For hunting guidance, open a technique's dossier. Use ⋯ to share or export a board to a teammate.

    EVIDENCE BOARD (0)

    Nothing flagged yet. On the STREAM, hit + FLAG on a case — or load a short example hunt from the current cases.

    Select an article for operator terms, or flag items with + on the Articles stream.

    THE INSIDER EVIDENCE MATRIX

    What real insider cases actually looked like — how the insider acted, what trail they left behind, and whether standard controls would have caught them. Built from court filings, not surveys.

    ALL CASES (mostly alleged) CONFIRMED IN COURT — a judge ruled it, or the insider admitted it ITM DETECTION CORROBORATED

    WHO — ACTOR PROFILE (roles, never individuals · coverage shown)

    FUNCTION

    EMPLOYMENT STATE AT THE ACT

    HOW INSIDERS ACTED — BY STAGE (tap a row for detail)

    WHERE THE EVIDENCE LIVES

    When a case is real, where does the proof turn up? Bar = share of cases that left a trail here. Darker = proven in court.

    LIMITATIONS — READ BEFORE CITING

    Selection bias: court data measures insiders who were caught, and whose cases were litigated — not insider behavior at large. Read every number as "of litigated insider cases" — equivalently, this is the evidence that survives to court: the definition of evidence a program should be able to produce. Small samples: percentages are suppressed below a floor of cases; counts are always shown. Attribution scope: technique ids are case-level, so evidence is scoped to cases exhibiting a technique. Collection bias: the corpus reflects our own query lexicon and sweep history. Records are machine-extracted from filings and normalized; confirmed-in-court and alleged are never conflated. ITM™ owned by Forscie Limited — not affiliated.

    METHODOLOGY & COLOPHON

    insider-intel is an open OSINT research instrument for discovering novel insider techniques — tradecraft that shows up in real cases before it shows up in any framework. It ingests litigated insider cases, insider-relevant news, first-person social confessions, and long-form publications; forensically enriches each case at ingest; and aggregates the corpus into evidence about how insider incidents actually happen and what record classes actually prove them.

    SIG
    Insider-confidence score, 0–100, assigned at ingest. The stream floor defaults to 30.
    PROOF STANDARD
    Every count separates CONFIRMED IN COURT (a judge ruled it happened, or the insider admitted it) from ALLEGED (claimed in a filing, not yet decided) from REPORTED (press or social only). They are never conflated.
    READ PATH
    No model runs at read time. Everything on screen is a projection of stored, append-only forensic records.
    PRIVACY
    Roles, never individuals — no persona graphs, no entity resolution across cases.
    EDITORIAL
    Findings publish by merge to main. The GitOps trail is the editorial record.
    ATTRIBUTION
    Insider Threat Matrix™ © Forscie Limited. This project is not affiliated with or endorsed by Forscie.

    Settings

    APPEARANCE

    Density
    Pane layout
    Keyboard reference
    j / k
    Next / previous case
    x
    Flag case to evidence board
    d
    Dismiss case
    Open source
    /
    Focus search

    STREAM DEFAULTS

    Live filters stay on the stream page — these set what a fresh session starts with.

    Default scope
    Default min. insider confidence — SIG ≥ 30

    DATA SOURCES

    Read-only inventory. Credentials live server-side — never in this static UI.

    • COURTLISTENERRECAP dockets + filings (trade secret, sabotage, insider fraud)ACTIVE
    • PACER PURCHASETargeted docket purchases for high-signal cases (budget-capped)ACTIVE
    • REDDITSubreddit streams via social subscriptionsACTIVE
    • XHandle timelines via social subscriptions (free-tier cadence)PAUSED
    • DATATHEFTNEWSCurated insider data-theft incident trackerACTIVE
    • TIPS (REDDIT RSS)Tip-lane RSS: r/netsec, r/cybersecurity, r/blueteamsec, r/DFIR, r/MalwareACTIVE

    Catalog and cadence are managed server-side. Social subscriptions below are the live controls from this UI.

    Sent as a bearer on write actions (subscriptions, flag-a-URL, reload). Stored only in this browser. Leave empty as a reader.

    SOCIAL SOURCES

    PUBLICATION SOURCES

    Long-form reference docs swept by the 6-hour refresh (curated catalog, server-side).

    SEI COMMON SENSE GUIDE 7E SEI POSITIVE DETERRENCE COLLECTION CISA INSIDER THREAT MITIGATION GUIDE NITTF INSIDER THREAT GUIDE 2017

    Curated catalog, refreshed with the corpus. One-off URLs can be flagged via the publications ingest API (operator token required in prod).