CRUSETRA

See what your scenarios catch, and what they flag incorrectly.

A scenario's threshold is the score above which it raises an alert.
Crusetra Monitoring runs seven scenarios at every threshold, over the alerts your analysts already closed.

git clone https://github.com/ArslaneSempai-ui/crusetra-monitoring cd crusetra-monitoring npm ci --ignore-scripts npm run measure:yours -- --alerts=your-alerts.csv --transactions=your-transactions.csv
The surveillance rack, state 01: The amount scenario alone catches 95.2% of the suspicious cases. amount scenario: recall 95.2%benign cases: false alerts 16.7%
finding 0116.7% of benign cases alerted

Scoring only the largest amount in the window catches 95.2% of the suspicious cases. It also alerts on 16.7% of the benign ones, because each of those is a one-off family purchase that the history explains.

95.2%catches 95.2% of suspicious cases with the amount scenario at 0.50, interval 84% to 99%, on 42 cases
16.7%false alerts 16.7% at 0.50, interval 8% to 31%, on 42 cases, all benign
The surveillance rack, state 02: The velocity scenario catches 28.6% of suspicious cases, and alerts on half the benign ones. velocity scenario: recall 28.6%benign cases: false alerts 50%
finding 0250% of benign cases alerted

Counting transactions catches 28.6% of the suspicious cases, because most of them are not the busiest accounts. The same count alerts on half the benign cases, which are payroll, seasonal trade and monthly savings.

28.6%catches 28.6% of suspicious cases with the velocity scenario at 0.50, interval 17% to 44%, on 42 cases
50%false alerts 50% at 0.50, interval 36% to 64%, on 42 cases, all benign
The surveillance rack, state 03: No scenario is sure of catching 90% of the suspicious cases. recall floor 90%: no scenario reaches itamount: closest at 84.2%
finding 03closest 84.2%

The tool keeps only the settings whose confidence interval stays above 90% of true cases, then among those picks the fewest false alerts. We chose that 90% floor ourselves, and you can move it. No scenario reaches it on the 42 cases: amount comes closest, at 84.2%, then peer at 75%.

84.2%amount at 0.50 comes closest: 84.2%, interval 84% to 99%
75%peer at 0.50 comes next: 75%, interval 75% to 95%
The surveillance rack, state 04: The amount scenario catches 100% of generated cases against 95.2% of the written ones. written cases: recall 95.2%generated cases: recall 100%
finding 04100% against 95.2%

The same setting catches 95.2% of the cases we wrote and 100% of the ones a script generated. A generated case is easier to spot, so it is counted on its own, and the rates above come from the cases we wrote.

95.2%catches 95.2% with amount at 0.50, on the cases we wrote, interval 84% to 99%
100%catches 100% at the same setting, on 126 cases a script generated, interval 97% to 100%
The surveillance rack, state 05: Run the same measurement on your own alert history. 84 cases written252 cases generated
finding 05one run, one report

The rates here come from our public test set: 42 cases marked suspicious and 42 cases marked benign, seven per typology, and another 126 cases of each kind that a script generated. Give the tool two CSV files from your systems, your closed alerts and their transactions, and it writes the report into the folder they are in.

42 cases42 cases suspicious and 42 cases benign, written by us, seven per typology
126 casesanother 126 cases of each kind, generated under a seed, and kept separate

Try the Monitoring instrument on our public test set.

Crusetra, explained.

The five Monitoring findings