Insider threats¶
The insider plugin detects anomalous USB and file activity volumes per actor, maps findings to MITRE ATT&CK techniques such as T1091 and T1020 when available, and produces explainable scores.
Status¶
Implemented behavioral spike detection (framework-native). A legacy LSTM demo remains at examples/legacy/lstm_usb_anomaly.py for research comparison.