09 · Behavioral detector

Behavioral

Looks at behavior, not just content. A single message may be ambiguous; a sequence of messages from a particular account, at a particular cadence, on a particular platform, often is not.

Channel
Patterns in account, session, and traffic behavior
Position
09 of 09

What it processes

Looks at behavior, not just content. A single message may be ambiguous; a sequence of messages from a particular account, at a particular cadence, on a particular platform, often is not.

Adversarial patterns it is tuned to catch

  • Coordinated grooming patterns across many accounts
  • Funnel patterns moving a target from a public surface to a private one
  • Account ages, posting cadence, and follow patterns characteristic of abuse
  • Re-use of toolkits across many surface accounts

Contribution to the ensemble verdict

Behavioral signal modulates per-message classification; a benign message in a known-hostile pattern receives heightened scrutiny.

Per-detector outputs are not a final verdict. The ensemble layer reads all nine and decides; the per-detector contribution is preserved in the evidence trace so the verdict remains auditable.