Observed arrival · 2026-08-29
ThreatFade Watches for Attackers Going Quiet
An open-source security engine that investigates adversarial activity becoming less observable across network and signal data.
Field notes
The project models changes in observable behavior rather than treating declining activity as automatically benign. Its stated pipeline extracts rolling-entropy and statistical features from PCAP, live signals, or supported telemetry, then carries structured evidence and confidence into analyst review. The page names three research scenarios—C2 quieting, LOTL gradual fade, and GNSS jamming—and lists JSON, Sigma-compatible, STIX 2.1-compatible, and SIEM/FusionOps handoff paths. The displayed release is v0.9.0-dev.
Observed signals
Read the marks
Editorial observations of this landing page, not a rating.
One card from the complete issue