The people and credentials you trust, watched like everything else.
BetaMost detection looks outward. Insider risk is a pack of 14 TillTell library rules pointed at a workspace’s own members and service credentials: the clone of every repository on someone’s last week, a repository made public, a mirror quietly pushing code elsewhere, secrets revealed in bulk, a detection turned down before something else happens. Shield → Insider risk ranks who set them off.
What the pack watches
Every rule starts in shadow: it records findings and never alerts. Promote the ones that suit your workspace on the TillTell rules page, or with tilldev shield tell rules stage <rule-id> advisory; they follow the same shadow → advisory → live lifecycle and demote themselves on false positives like any other rule.
Members
| Rule | Level | ATT&CK |
|---|---|---|
| Workspace approvals or required two-factor turned off tell-insider-guardrail-off | High | attack.t1685, attack.t1556.006 |
| One person cloned many repositories tell-insider-mass-clone | High | attack.t1213.003 |
| Mirror host allowed, then a push mirror set up tell-insider-mirror-host-then-push | High | attack.t1567.001 |
| One person deleted several repositories tell-insider-repo-delete-burst | High | attack.t1485 |
| Private repository made public tell-insider-repo-made-public | High | attack.t1567 |
| Repository encryption key destroyed tell-insider-repos-erased | High | attack.t1485 |
| One person deleted many secrets tell-insider-secret-mass-delete | High | attack.t1485 |
| One person revealed many secret values tell-insider-secret-reveal-burst | High | attack.t1555 |
| Several detections turned down by one person tell-insider-detection-weakened | Medium | attack.t1685 |
| Repository set to push to an outside host tell-insider-push-mirror | Medium | attack.t1567.001 |
| Secrets read from a project the person has not used tell-insider-secret-new-project | Low | attack.t1555 |
Service credentials
API keys, TillSecrets service tokens and machine SSH keys. These rules learn what each credential normally does and flag the first time it does something else, once it has enough history to judge.
| Rule | Level | ATT&CK |
|---|---|---|
| Service credential created another credential tell-service-mints-credential | Medium | attack.t1098.001 |
| Service credential doing something new tell-service-new-action | Medium | attack.t1078.004 |
| Service credential reading a new environment tell-service-new-environment | Medium | attack.t1555 |
What it reads
Nothing new is collected from people’s devices. The pack reads records your TillDev products already keep, through the same security stream as every other TillTell rule:
| Record | What is in it |
|---|---|
| Repository reads | Every authenticated git fetch or clone over HTTPS or SSH, against the person or the machine key that made it. |
| Repository changes | Visibility changes with what they changed from and to, mirrors and the hosts they may push to, deletions and erasures. |
| Secrets | TillSecrets reads, reveals, leases and deletions, with the project and environment. |
| Workspace settings | Required two-factor sign-in, step-up policies, API keys created, and TillTell rule stages and deletions. |
Anonymous reads of public repositories and fetches with a deploy token are not recorded, and an API key acts as a credential, never as the person who made it.
How a score is made
A row is one member or one credential. Its score adds up the pack’s findings about it in the window (7, 30, 90 days; 30 by default) by level: critical 8, high 4, medium 2, low 1. Rows are ordered by score, then by open findings, then by the latest.
- Findings triaged as a false positive, benign or a duplicate stay listed and stop counting.
- Drill findings, findings with no actor and rules outside the pack are left out.
- Someone who has since left the workspace keeps their row, marked as such.
- One read covers the 5,000 latest findings and ranks up to 200 rows; when more fired, the page says so and a shorter window shows the rest.
Who sees it
Owners and admins only, on the page, the CLI and the API. Opening a finding leads to TillTell, where it is triaged like any other; a verdict there is what takes it out of a score.
From the CLI and the API
tilldev shield insider # members and credentials flagged in the last 30 days, highest score first
tilldev shield insider --days 90 # 7, 30, 90
tilldev shield insider show <actor-id> # the findings behind one row
tilldev shield insider rules # the pack, each rule's stage here and its findings
tilldev shield tell rules stage tell-insider-repo-made-public advisory # start alerting on oneThe API is GET /api/v1/shield/insider with days, and GET /api/v1/shield/insider/findings with actor and days. See the API reference.