Is someone checking your browsing? This website will appear in your browser history. If you're concerned someone may be monitoring your internet use, consider using a trusted friend's device, a library computer, or your browser's private/incognito mode. You can press Quick Exit or hit Escape at any time to leave this site quickly. Learn more about staying safe online

Changelog

A log of substantive changes to the TFA Matrix website and underlying framework. Subscribe via RSS, or for the detailed commit history see the project repository.

2026-04-21 — Site audit pass: safety disclaimers, mitigations, and metadata

Editorial pass prompted by review of site content.

  • Content All technique and tactic pages — Reordered safety disclaimer so "Always consider your physical safety first" leads. Added caveat to "What You Can Do" sections noting the list is not exhaustive.
  • Content SAFE-T-0072 Stalkerware Installation (+ all sub-techniques) — Added notice that a normally-performing device is not proof of safety — modern stalkerware runs quietly.
  • Content SAFE-T-0082 Credential Theft — Added Have I Been Pwned as a public action and as a technical mitigation (SAFE-M-0181 Credential Breach Monitoring).
  • Content SAFE-T-0079 Calendar/Schedule Surveillance — Expanded calendar sharing instructions from Google Calendar only to cover Apple iCloud, Microsoft Outlook / Microsoft 365, Samsung, Proton, and Fastmail.
  • Content SAFE-TA-0001 Surveillance & Tracking; SAFE-T-0161; techniques index — Cross-references to SAFE-T-0145 (Technology Abuse Through Custody Arrangements) are now hyperlinks.
  • Structure All technique and tactic pages — Public view now shows the metadata card (ID, tactic, created, last modified) previously only visible in the technical view.
  • Infrastructure Site-wide — Added sitemap.xml listing all published pages.