FAIR cyber risk quantification toolkit: agent-based control simulation, threat event frequency estimator, LLM classification validator, Monte Carlo risk engine.
Part of Apropos Security · Notebooks · Library (pip) · Blog
Monte Carlo simulation tool for FAIR (Factor Analysis of Information Risk) methodology with industry benchmarks.
Features: LEF/LM simulation, portfolio aggregation, sensitivity analysis, IRIS 2025 benchmarks
License: CC BY-NC-SA 4.0 (Non-Commercial Use Only)
Agent-based simulation of FAIR-CAM control dynamics. Reproduction package for Jones & Voicu (2026), "Control Physiology: An Agent-Based Model of FAIR-CAM Dynamics."
Features: 8 agent types, multiplicative defense-in-depth, three-source variance model, budget-constrained remediation, narrative causation engine, empirically calibrated loss magnitudes
License: CC BY-NC-SA 4.0 (Non-Commercial Use Only)
Data-grounded Threat Event Frequency estimation with vector decomposition. Produces defensible TEF estimates for FAIR risk quantification by decomposing threat frequency into four initial access vectors.
Features: Four-vector decomposition (exploitation, credential, phishing, supply chain), three-anchor base rate triangulation, cross-vector dampening (VERIS-calibrated), credibility blending with org telemetry, web UI, CLI, continuous telemetry monitoring
Install: pip install tef-estimator · PyPI
License: CC BY-NC-SA 4.0 (Non-Commercial Use Only)
Read More | User Guide | Technical Reference
Five-dimension psychometric validation framework for LLM-generated classifications. Tests whether an LLM's outputs are reliable enough to trust, using the same statistical methods applied to human raters.
Features: Coherence (inter-rater kappa), consistency (rule-based checks), convergent validity (reference comparison), adversarial discrimination (minimal pairs), stability and sensitivity (paraphrase invariance), interactive dashboard, configurable thresholds, bootstrap confidence intervals
Install: pip install llm-classification-validator · PyPI
License: CC BY-NC-SA 4.0 (Non-Commercial Use Only)
Read More | Methodology | Examples
This repository uses multiple licenses.
- Individual tools: Each has its own license (see tool directories)