Skip to content
#

insider-threat

Here are 79 public repositories matching this topic...

The principal objective of this project is to develop a knowledge base of the tactics, techniques, and procedures (TTPs) used by insiders in the IT environment. It will establish an Insider Threat TTP Knowledge Base, built upon data collected on insider threat incidents and lessons learned and experience from the ATT&CK knowledge base.

  • Updated Jul 6, 2026
  • Python

Proxilion MCP Security Gateway is a self-hosted, Docker-ready security gateway that provides real-time threat detection (<50ms P95 latency) against insider threats, compromised accounts, and rogue AI agents by analyzing tool calls from assistants like Copilot and Claude Code, achieving a 75-85% detection rate against sophisticated attacks.

  • Updated May 31, 2026
  • Rust

Patent-aligned cybersecurity prototype implementing dynamic trust-based adaptive access control using credential integrity, competence evidence, behavioral risk, and event-driven trust recomputation.

  • Updated Apr 11, 2026
  • Python
SENTINEL

SENTINEL is an immersive insider threat detection and training platform designed for security analysts, SOC teams, and IT professionals. Featuring a fully simulated UEBA (User and Entity Behavior Analytics) environment, interactive threat simulations, and comprehensive indicators of compromise (IOCs) library🔒👨🏿‍💻.

  • Updated Mar 3, 2026
  • HTML

Public docs for Black Box by Alcyone Secure — a forensic flight recorder for Windows that keeps tamper-evident, hash-chained logs of what happens to a device in someone else's hands: repair shops, insider threats, device handovers. Complements EDR/DLP; aligned with DPDP Act 2023 & GDPR.

  • Updated Aug 27, 2026

Add this topic to your repo

To associate your repository with the insider-threat topic, visit your repo's landing page and select "manage topics."

Learn more