Insider Threat Matrix™Insider Threat Matrix™
HumanSynthetic
  • Sponsors
  • About Us
  • Contributors
  • Sponsors
  • About Us
  • Contributors
HumanSynthetic

Waiting/typing...

Detections
Preventions
Github

Invocation

Agent-to-Agent and Tool-Output Invocation

Autonomous Self-Invocation

  • Recursive Self-Invocation
  • Runtime-Control Modification Invocation
  • Scheduled Self-Invocation
  • Self-Spawned Process Invocation

Deconstructed and Staged Invocation

Indirect Untrusted-Content Invocation

MCP Invocation

  • Connect-Time Tool Metadata Invocation
  • Cross-Server Tool Shadowing Invocation
  • Hidden Terminal-Control Invocation
  • MCP Prompt Template Invocation
  • MCP Resource Content Invocation
  • MCP Sampling Invocation
  • MCP Tool-Output Invocation

Memory-Resident Invocation

Operator Invocation

  • Authorized Operator Invocation
  • Unauthorized Operator Invocation

Triggered and Delayed Invocation

  • Synthetic Insider Threat Matrix™
  • -SAR3
  • ID: SAR3
  • Created: 26th August 2026
  • Updated: 26th August 2026

Invocation

The inputs or triggers that cause a synthetic subject to act.

Sections (8)

  • About us
  • Contributors
  • Sponsors
  • Privacy Policy
  • Terms of use
  • Manage Cookies

The Insider Threat Matrix™ is an open framework for computer-enabled insider threat investigations.


© 2026 Forscie Limited. All rights reserved. Insider Threat Matrix™ is a trademark of Forscie Limited.

  • GitHub
  • X
  • Reddit
  • LinkedIn