insider-intel

LEARN INSIDER TRADECRAFT FROM REAL COURT CASES

LIVE

Connecting…

Latest

    Workbench

    The Workbench collects cases you flag with + FLAG from the stream. MODUS OPERANDI assembles them into a forensic case study — what each insider actually did, from stored court/report forensics. Use ⋯ to share, export, or import a board.

    The Workbench

    Flag cases from the stream with + FLAG and they land on the evidence board here. MODUS OPERANDI then shows the ITM techniques those insiders used, with per-case evidence and the traces each behavior leaves. For hunting guidance, open a technique's dossier. Use ⋯ to share or export a board to a teammate.

    EVIDENCE BOARD (0)

    Nothing flagged yet. On the STREAM, hit + FLAG on a case — or load a short example hunt from the current cases.

    Select an article for operator terms, or flag items with + on the Articles stream.

    THE INSIDER EVIDENCE MATRIX

    What real insider cases actually looked like — how the insider acted, what trail they left behind, and whether standard controls would have caught them. Built from court filings, not surveys.

    ALL CASES (mostly alleged) CONFIRMED IN COURT — a judge ruled it, or the insider admitted it ITM DETECTION CORROBORATED

    WHO — ACTOR PROFILE (roles, never individuals · coverage shown)

    FUNCTION

    EMPLOYMENT STATE AT THE ACT

    HOW INSIDERS ACTED — BY STAGE (tap a row for detail)

    WHERE THE EVIDENCE LIVES

    When a case is real, where does the proof turn up? Bar = share of cases that left a trail here. Darker = proven in court.

    Tooling

    Enterprise tools for insider-threat programs — with each product's court-filing record.

    ABOUT

    Built and run by Tim Carreira. Code and data are public. Insider case corpus from US, Canadian, and Indian court records, updated daily. Follow it: FEED.XML.

    Insider Threat Matrix™ © Forscie Limited — not affiliated. US court records via CourtListener / Free Law Project. Indian judgments from the Indian High Court Judgments open dataset (eCourts records, CC BY license, hosted on the AWS Open Data Registry). Canadian decisions via CanLII court feeds.

    RESEARCH

    Long-form findings from the corpus. Each briefing is dated and frozen as of its publication; the live, recomputed numbers are on EVIDENCE.

    Settings

    APPEARANCE

    STREAM DEFAULTS

    Live filters stay on the stream page — these set what a fresh session starts with.

    Default scope
    Default min. insider confidence — SIG ≥ 30

    DATA SOURCES

    Every ingestion lane is smoke-tested each refresh cycle. A lane counts as BROKEN after three failed or empty cycles in a row.

    No lane telemetry yet — the health line fills when the corpus data loads.