TILLSHIELD · INSIDER RISK

The people and credentials you trust, watched like everything else.

Beta

Most detection looks outward. Insider risk is a pack of 14 TillTell library rules pointed at a workspace’s own members and service credentials: the clone of every repository on someone’s last week, a repository made public, a mirror quietly pushing code elsewhere, secrets revealed in bulk, a detection turned down before something else happens. Shield → Insider risk ranks who set them off.

A reason to look, never a verdict
Every rule here also fires on ordinary work: a new laptop clones everything, an engineer cleans up old secrets, an admin tunes a noisy rule. A score says where to look first. Decide with the person and the context, and mark what turns out benign so it stops counting.
01The pack

What the pack watches

Every rule starts in shadow: it records findings and never alerts. Promote the ones that suit your workspace on the TillTell rules page, or with tilldev shield tell rules stage <rule-id> advisory; they follow the same shadow → advisory → live lifecycle and demote themselves on false positives like any other rule.

Members

RuleLevelATT&CK
Workspace approvals or required two-factor turned off
tell-insider-guardrail-off
Highattack.t1685, attack.t1556.006
One person cloned many repositories
tell-insider-mass-clone
Highattack.t1213.003
Mirror host allowed, then a push mirror set up
tell-insider-mirror-host-then-push
Highattack.t1567.001
One person deleted several repositories
tell-insider-repo-delete-burst
Highattack.t1485
Private repository made public
tell-insider-repo-made-public
Highattack.t1567
Repository encryption key destroyed
tell-insider-repos-erased
Highattack.t1485
One person deleted many secrets
tell-insider-secret-mass-delete
Highattack.t1485
One person revealed many secret values
tell-insider-secret-reveal-burst
Highattack.t1555
Several detections turned down by one person
tell-insider-detection-weakened
Mediumattack.t1685
Repository set to push to an outside host
tell-insider-push-mirror
Mediumattack.t1567.001
Secrets read from a project the person has not used
tell-insider-secret-new-project
Lowattack.t1555

Service credentials

API keys, TillSecrets service tokens and machine SSH keys. These rules learn what each credential normally does and flag the first time it does something else, once it has enough history to judge.

RuleLevelATT&CK
Service credential created another credential
tell-service-mints-credential
Mediumattack.t1098.001
Service credential doing something new
tell-service-new-action
Mediumattack.t1078.004
Service credential reading a new environment
tell-service-new-environment
Mediumattack.t1555
02Records

What it reads

Nothing new is collected from people’s devices. The pack reads records your TillDev products already keep, through the same security stream as every other TillTell rule:

RecordWhat is in it
Repository readsEvery authenticated git fetch or clone over HTTPS or SSH, against the person or the machine key that made it.
Repository changesVisibility changes with what they changed from and to, mirrors and the hosts they may push to, deletions and erasures.
SecretsTillSecrets reads, reveals, leases and deletions, with the project and environment.
Workspace settingsRequired two-factor sign-in, step-up policies, API keys created, and TillTell rule stages and deletions.

Anonymous reads of public repositories and fetches with a deploy token are not recorded, and an API key acts as a credential, never as the person who made it.

03Scoring

How a score is made

A row is one member or one credential. Its score adds up the pack’s findings about it in the window (7, 30, 90 days; 30 by default) by level: critical 8, high 4, medium 2, low 1. Rows are ordered by score, then by open findings, then by the latest.

  • Findings triaged as a false positive, benign or a duplicate stay listed and stop counting.
  • Drill findings, findings with no actor and rules outside the pack are left out.
  • Someone who has since left the workspace keeps their row, marked as such.
  • One read covers the 5,000 latest findings and ranks up to 200 rows; when more fired, the page says so and a shorter window shows the rest.
04Access

Who sees it

Owners and admins only, on the page, the CLI and the API. Opening a finding leads to TillTell, where it is triaged like any other; a verdict there is what takes it out of a score.

05CLI and API

From the CLI and the API

sh
tilldev shield insider                       # members and credentials flagged in the last 30 days, highest score first
tilldev shield insider --days 90              # 7, 30, 90
tilldev shield insider show <actor-id>        # the findings behind one row
tilldev shield insider rules                  # the pack, each rule's stage here and its findings

tilldev shield tell rules stage tell-insider-repo-made-public advisory   # start alerting on one

The API is GET /api/v1/shield/insider with days, and GET /api/v1/shield/insider/findings with actor and days. See the API reference.