Insider Threat Matrix™Insider Threat Matrix™
HumanSynthetic
  • Sponsors
  • About Us
  • Contributors
  • Sponsors
  • About Us
  • Contributors
HumanSynthetic

Waiting/typing...

Detections
Preventions
Chains Github
  • AR5
  • -AF020
AF020

Deletion of Volume Shadow Copy - AR5

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Section AF020
  • AR3
  • -PR020
  • -PR020.003
PR020.003

Misclassification of Sensitivity Labels - AR3

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Subsection PR020.003
  • Detections
  • -DT087
DT087

USB MountPoints2 - DT087

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Detection DT087
  • Detections
  • -DT091
DT091

MFT Entry Number Sequence Irregularities - DT091

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Detection DT091
  • Detections
  • -DT092
DT092

MFT Unusual Timestamp Patterns - DT092

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Detection DT092
  • Detections
  • -DT093
DT093

MFT and Shimcache Executable Timestamp Comparison - DT093

Contributor: Joshua Phillips @ Senior SOC Analyst, Viasat - Detection DT093
  • About us
  • Contributors
  • Sponsors
  • Privacy Policy
  • Terms of use
  • Manage Cookies

The Insider Threat Matrix™ is an open framework for computer-enabled insider threat investigations.


© 2026 Forscie Limited. All rights reserved. Insider Threat Matrix™ is a trademark of Forscie Limited.

  • GitHub
  • X
  • Reddit
  • LinkedIn