Latest
Maps to
No direct ITM map — articles below may still help.
Detections that catch it
Observed evidence
From real cases exhibiting this technique (case-scoped). ✓ = the ITM detection is corroborated by case evidence; bars = share of this technique's cases whose record trail includes the class (darker = confirmed in court).
How to hunt this
Tool-agnostic methods distilled from what the insiders in these cases actually did — how to spot the behavior and how to counter it (telemetry, process, and people), with no case-specific names. Copy the LLM prompt to have your AI assistant tailor them to your organization.
Related preventions
Cases
Reported incidents and coverage matching this technique. Flag with + to build a hunt.
MODUS OPERANDI
Techniques observed
Behaviors
Insider Threat Matrix™
ITM™ © Forscie Limited — not affiliated.
Workbench
The Workbench collects cases you flag with + FLAG from the stream. MODUS OPERANDI assembles them into a forensic case study — what each insider actually did, from stored court/report forensics. Use ⋯ to share, export, or import a board.The Workbench
Flag cases from the stream with + FLAG and they land on the evidence board here. MODUS OPERANDI then shows the ITM techniques those insiders used, with per-case evidence and the traces each behavior leaves. For hunting guidance, open a technique's dossier. Use ⋯ to share or export a board to a teammate.
EVIDENCE BOARD (0)
Nothing flagged yet. On the STREAM, hit + FLAG on a case — or load a short example hunt from the current cases.
Select an article for operator terms, or flag items with + on the Articles stream.
Case record
Structured facts extracted by the ingest analyst model.
Operator search terms
Click a term to copy one, or Copy terms for the full set.
ITM techniques
Related detections
SIEM / IR handoff from matched techniques.
THE INSIDER EVIDENCE MATRIX
What real insider cases actually looked like — how the insider acted, what trail they left behind, and whether standard controls would have caught them. Built from court filings, not surveys.
FINDINGS (versioned · operator-approved by merge · numbers cite the stated ledger run)
WHO — ACTOR PROFILE (roles, never individuals · coverage shown)
FUNCTION
EMPLOYMENT STATE AT THE ACT
HOW INSIDERS ACTED — BY STAGE (tap a row for detail)
WHERE THE EVIDENCE LIVES
When a case is real, where does the proof turn up? Bar = share of cases that left a trail here. Darker = proven in court.
LIMITATIONS — READ BEFORE CITING
Selection bias: court data measures insiders who were caught, and whose cases were litigated — not insider behavior at large. Read every number as "of litigated insider cases" — equivalently, this is the evidence that survives to court: the definition of evidence a program should be able to produce. Small samples: percentages are suppressed below a floor of cases; counts are always shown. Attribution scope: technique ids are case-level, so evidence is scoped to cases exhibiting a technique. Collection bias: the corpus reflects our own query lexicon and sweep history. Records are machine-extracted from filings and normalized; confirmed-in-court and alleged are never conflated. ITM™ owned by Forscie Limited — not affiliated.
METHODOLOGY & COLOPHON
insider-intel is an open OSINT research instrument for discovering novel insider techniques — tradecraft that shows up in real cases before it shows up in any framework. It ingests litigated insider cases, insider-relevant news, first-person social confessions, and long-form publications; forensically enriches each case at ingest; and aggregates the corpus into evidence about how insider incidents actually happen and what record classes actually prove them.
- SIG
- Insider-confidence score, 0–100, assigned at ingest. The stream floor defaults to 30.
- PROOF STANDARD
- Every count separates CONFIRMED IN COURT (a judge ruled it happened, or the insider admitted it) from ALLEGED (claimed in a filing, not yet decided) from REPORTED (press or social only). They are never conflated.
- READ PATH
- No model runs at read time. Everything on screen is a projection of stored, append-only forensic records.
- PRIVACY
- Roles, never individuals — no persona graphs, no entity resolution across cases.
- EDITORIAL
- Findings publish by merge to main. The GitOps trail is the editorial record.
- ATTRIBUTION
- Insider Threat Matrix™ © Forscie Limited. This project is not affiliated with or endorsed by Forscie.
Settings
APPEARANCE
- j / k
- Next / previous case
- x
- Flag case to evidence board
- d
- Dismiss case
- ⏎
- Open source
- /
- Focus search
STREAM DEFAULTS
Live filters stay on the stream page — these set what a fresh session starts with.
DATA SOURCES
Read-only inventory. Credentials live server-side — never in this static UI.
- COURTLISTENERRECAP dockets + filings (trade secret, sabotage, insider fraud)ACTIVE
- PACER PURCHASETargeted docket purchases for high-signal cases (budget-capped)ACTIVE
- REDDITSubreddit streams via social subscriptionsACTIVE
- XHandle timelines via social subscriptions (free-tier cadence)PAUSED
- DATATHEFTNEWSCurated insider data-theft incident trackerACTIVE
- TIPS (REDDIT RSS)Tip-lane RSS: r/netsec, r/cybersecurity, r/blueteamsec, r/DFIR, r/MalwareACTIVE
Catalog and cadence are managed server-side. Social subscriptions below are the live controls from this UI.
Sent as a bearer on write actions (subscriptions, flag-a-URL, reload). Stored only in this browser. Leave empty as a reader.
SOCIAL SOURCES
PUBLICATION SOURCES
Long-form reference docs swept by the 6-hour refresh (curated catalog, server-side).
Curated catalog, refreshed with the corpus. One-off URLs can be flagged via the publications ingest API (operator token required in prod).
Subscribed
Nothing subscribed yet.
Suggested