HOW TO USE THIS SITE
Real court cases about insiders — employees and contractors who stole data, took secrets to a competitor, or sabotaged systems. We break down what they did, the trail they left, and what finally caught them. Built for security teams — readable by anyone.
- BUILD A PROGRAM
- Starting a defense from scratch? EVIDENCE shows which security measures actually caught insiders in real cases. The PUBLICATIONS channel on STREAM collects the standard how-to guides.
- DETECT
- Want to spot an insider in the act? MATRIX › Detections — every tactic lists the warning signs that revealed it, with the cases where that happened.
- PREVENT
- Want to stop it before it starts? MATRIX › Preventions lists the safeguards matched to the tactics real insiders used.
- HUNT
- Worried it already happened? Search a scenario on STREAM, flag the matching cases with +, then open WORKBENCH to see step-by-step what those insiders did — and what to look for in your own logs.
TAB CHEAT SHEET
- STREAM
- The live feed — new court cases and news stories, newest first. Press / to search, + to save a case for later. (Keyboard: j/k move · x save · d hide · ⏎ open.)
- MATRIX
- The catalog of insider tactics, stage by stage. Click any tactic to see the real cases where it was used and what caught it.
- EVIDENCE
- The proof that shows up when insiders get caught — the records, logs, and witnesses real cases cite. FINDINGS reads as a short report: a bottom line, then numbered findings F1 onward grouped by the question each answers; WHAT CHANGED tracks which tactics rise and fall by filing year. Jurisdiction tabs give each court system its own report; TACTICS BY REGION shows which techniques skew regional.
- TOOLING
- Security products named in real court filings — which caught insiders, which got bypassed. Click a product for its cases.
- WORKBENCH
- Your saved cases, side by side. Save cases on STREAM with +, then compare what those insiders actually did here.
- SETTINGS
- How the site opens for you — how much it shows, how strict the signal filter starts, and admin tools like forcing a data refresh.
TRUST — every claim links back to cited court filings, and we never blur the line between what a court CONFIRMED and what a filing merely ALLEGED. Every summary also says where it came from: provenance is stamped on each card.
ABOUT — what this site is, where the data comes from, and who runs it. Open ABOUT →
Latest
Maps to
No direct ITM map — articles below may still help.
Detections that catch it
Observed evidence
From real cases exhibiting this technique (case-scoped). ✓ = the ITM detection is corroborated by case evidence; bars = share of this technique's cases whose record trail includes the class (darker = confirmed in court).
How to hunt this
Tool-agnostic methods distilled from what the insiders in these cases actually did — how to spot the behavior and how to counter it (telemetry, process, and people), with no case-specific names. Copy the LLM prompt to have your AI assistant tailor them to your organization.
Related preventions
Relevant tooling
Which class of tooling helps here — tool categories whose mapped ITM controls intersect this technique's detections and preventions, ordered by control overlap (detections first). Tap a category for its coverage dossier; vendor chips count documented case mentions, never effectiveness.
Cases
Reported incidents and coverage matching this technique. Flag with + to build a hunt.
MODUS OPERANDI
Techniques observed
Behaviors
Insider Threat Matrix™
ITM™ © Forscie Limited — not affiliated.
Workbench
The Workbench collects cases you flag with + FLAG from the stream. MODUS OPERANDI assembles them into a forensic case study — what each insider actually did, from stored court/report forensics. Use ⋯ to share, export, or import a board.The Workbench
Flag cases from the stream with + FLAG and they land on the evidence board here. MODUS OPERANDI then shows the ITM techniques those insiders used, with per-case evidence and the traces each behavior leaves. For hunting guidance, open a technique's dossier. Use ⋯ to share or export a board to a teammate.
EVIDENCE BOARD (0)
Nothing flagged yet. On the STREAM, hit + FLAG on a case — or load a short example hunt from the current cases.
Select an article for operator terms, or flag items with + on the Articles stream.
Case record
Structured facts extracted by the ingest analyst model.
Operator search terms
Click a term to copy one, or Copy terms for the full set.
ITM techniques
Related detections
SIEM / IR handoff from matched techniques.
THE INSIDER EVIDENCE MATRIX
What real insider cases actually looked like — how the insider acted, what trail they left behind, and whether standard controls would have caught them. Built from court filings, not surveys.
FINDINGS (derived from this jurisdiction's ledger on every load · no stored numbers)
Numbered findings, strongest first, grouped by the question each answers — open a group to read it. Switching jurisdiction re-states every one.
WHO — ACTOR PROFILE (roles, never individuals · coverage shown)
FUNCTION
EMPLOYMENT STATE AT THE ACT
WHAT CHANGED — TECHNIQUES BY FILING YEAR (filing year · METHODOLOGY on hover)
Which tactics show up more, and less, over time. Each cell is the number of cases filed that year.
HOW INSIDERS ACTED — BY STAGE (tap a row for detail)
WHERE THE EVIDENCE LIVES
When a case is real, where does the proof turn up? Bar = share of cases that left a trail here. Darker = proven in court.
TACTICS BY REGION (per-jurisdiction case counts · METHODOLOGY on hover)
Which insider tactics skew regional — the same techniques, counted per court system. SKEWS marks a technique whose cases concentrate in one jurisdiction.
Tooling
Enterprise tools for insider-threat programs — with each product's court-filing record.
One tool category against the observed case record — how much real insider-case volume its mapped ITM controls cover, where court records credit the control class with the catch, which vendors the case documents actually name, and the observed techniques it reaches. All numbers recompute from the live corpus on every sweep.
NAMED IN CASE RECORDS
IMPLEMENTS — ITM CONTROL ENTRIES
COVERS THESE OBSERVED TECHNIQUES
NAMED IN THESE FILINGS
ABOUT
Built and run by Tim Carreira. Code and data are public. Insider case corpus from US, Canadian, and Indian court records, updated daily. Follow it: FEED.XML.
Insider Threat Matrix™ © Forscie Limited — not affiliated. US court records via CourtListener / Free Law Project. Indian judgments from the Indian High Court Judgments open dataset (eCourts records, CC BY license, hosted on the AWS Open Data Registry). Canadian decisions via CanLII court feeds.
Settings
APPEARANCE
STREAM DEFAULTS
Live filters stay on the stream page — these set what a fresh session starts with.
DATA SOURCES
Every ingestion lane is smoke-tested each refresh cycle. A lane counts as BROKEN after three failed or empty cycles in a row.
No lane telemetry yet — the health line fills when the corpus data loads.