- FBI and Everfox’s insider threat capabilities are now fully operational across the enterprise
- Everfox provided engineering, configuration and technical support
- The FBI retained responsibility for mission direction, governance and strategic priorities
The FBI has fully deployed insider threat capabilities from Everfox, covering numerous endpoints on multiple FBI networks.
The Herndon, Virginia-based defense technology company said Wednesday the agency has achieved full compliance with Committee on National Security Systems Directive 504 following the deployment. The directive sets minimum user activity monitoring requirements for insider threats.
How Did the FBI & Everfox Share Program Responsibilities?
Everfox, under a contract with the FBI, handled the technical side of the effort, providing engineering support, configuring the technology and working with FBI stakeholders on day-to-day activities. The bureau retained oversight of the program, including mission direction, governance and strategic priorities.
What Capabilities Are Now Operational?
The deployment includes user activity monitoring and behavioral analytics designed to help the FBI identify potential insider threats in its enterprise. The capabilities are now fully operational across the networks covered by the effort.
FBI Director Kash Patel said the agency worked with Everfox to detect and respond to insider threats on its most sensitive networks while meeting federal security standards.
What Did Everfox Say About Insider Threats?
Everfox Chairman and CEO Dave Wajsgras said insider-risk threats are becoming more complex and that early visibility into unusual behavior is important for national security.
“Our platform fuses behavior context with advanced analytics and is trusted across a multitude of defense and intelligence agencies,” said the nine-time Wash100 Award winner.
The FBI’s implementation comes as federal agencies continue to update their approaches to insider-threat mitigation. The Cybersecurity and Infrastructure Security Agency recently released an updated Insider Threat Mitigation Guide addressing areas including early risk detection, access control and emerging workplace risks.
CISA also previously issued guidance on establishing multidisciplinary insider-threat management teams, outlining organizational practices for planning, executing and maintaining an insider-threat program.


