◇ The Canine Engine · Our Methodology

Threat-intelligence doctrine. Encoded as software.

Project Canine was not built from a feature list. It was built from the discipline of the intelligence cycle — direction, collection, processing, analysis, dissemination — applied to cyber threat intelligence and enforced by the platform on every engagement, every time.

CHAPTER 01 · DIRECTION

Every Engagement Starts with a Requirement

Cyber threat intelligence does not start with data. It starts with direction — a priority intelligence requirement, stated precisely enough that an analyst knows what would satisfy it and what would not. "Which of our internet-facing assets carries exploitable exposure?" "Has credential material tied to our domains surfaced in known exposure datasets?" "What does this vendor's external posture say about the risk of connecting them to our environment?"

The requirement decides everything downstream — what gets collected, what counts as a finding, what belongs in the intelligence product, and when collection stops. An engagement without a requirement is not intelligence work; it is data-gathering without a purpose.

This work is often mischaracterized as a tooling problem. It isn't. Feeds come and go, queries rot, sources degrade overnight. What persists is a disciplined requirements process and a particular way of reading what collection returns.

Collection without direction produces data, not intelligence. The requirement is what turns what we gather into a product a defender can act on.

Each requirement is scoped against the threat model that matters to the client: the initial-access techniques actually used against their sector, the exposure classes that historically convert into incidents, the assets whose compromise would cascade. Direction is where defensive relevance is decided — before a single query is run.

CHAPTER 02 · COLLECTION

Multi-Source Collection Across the External Estate

Collection runs against the externally observable estate — the same surface any threat actor can enumerate without touching a perimeter. DNS and passive-DNS history. Certificate transparency logs. Internet-wide scan data. Mail authentication posture — SPF, DKIM, DMARC. Known credential-exposure datasets and publicly exposed data. Public advisories, vendor disclosures, and vulnerability intelligence. Corporate registries where the requirement demands third-party context.

Each source is tasked deliberately against the requirement — a collection plan, not a dragnet. We collect nothing privileged and nothing intrusive: no exploitation, no authentication attempts, no interaction beyond what a passive observer performs. The value is precisely that the picture is assembled from what is already exposed.

COLLECTION DISCIPLINE

Every Pass Grades Two Things

A collection pass returns two products in parallel. It returns observations about the estate — live hosts, certificate history, credential exposure, configuration drift. And it grades collection itself: source coverage, data freshness, and the confidence ceiling the evidence base can support. An intelligence product that does not know the limits of its own collection is not finished work.

Collection gaps are recorded as findings in their own right. "No visibility into this asset class from open sources" is intelligence — it defines the boundary between what is assessed and what is assumed, and it is written into the product rather than papered over.

CHAPTER 03 · PROCESSING

The Corroboration Engine

Raw collection is telemetry, not intelligence. Processing is where the platform normalises, deduplicates, and enriches what collection returns — and where the single most important control in the doctrine is enforced: no single-source observation is ever promoted on its own.

Every observation enters the working layer as an assumption carrying a probability, not a verdict. An exposed service, a credential in a known exposure dataset, a stale certificate — each shifts the likelihood of competing hypotheses about the estate. Assumptions are not the deliverable. The corroborated synthesis is.

CORE PRINCIPLE

The Convergence Test

An assumption is promoted to a finding only when independent sources converge. A credential appearing in one exposure dataset is an indicator. The same credential material surfacing in a second, unrelated dataset — tied to mail infrastructure that passive DNS confirms is still live — is a corroborated finding about current exposure, because artifacts with no reason to agree, agreed. Convergence of independent sources is the strongest signal in intelligence work, and the engine will not promote without it.

Once a finding passes the convergence test, it is re-tasked as a new collection pivot — sibling domains, shared infrastructure, adjacent services with a statistically higher likelihood of carrying the same exposure class. The cycle iterates from corroborated fact, never from speculation.

CHAPTER 04 · ANALYSIS

One Evidence Base, Four Analytic Lenses

Analysis is where corroborated findings become assessed intelligence. There is a temptation to describe CTI as a single workflow with a single toolset. That is not how the discipline works. The same evidence base supports very different intelligence requirements, and the difference lives almost entirely in the analytic framework applied to it.

A junior analyst watching the same query run against three different estates would see three identical sessions. The interpretation, the pivots that follow, and the assessments written into the working layer would be completely different in each case. The lens is doing the analytic work, not the tool.

Technical

Exposure & Posture

How exposed is this estate, and what does its posture say about its operational discipline? Attack surface, credential hygiene, patch cadence, configuration health, and the drift between them. The tightest natural boundary of the four lenses.

Human

Workforce Exposure

How does people-level exposure change the estate's threat profile? Credential reuse, presence in known exposure datasets, and the workforce information that fuels phishing and social-engineering pretexts — assessed in aggregate, to harden the organisation, never to profile individuals.

Organizational

Narrative Coherence

Does the entity's story hold together over time? A vendor whose infrastructure history contradicts its stated business is not necessarily doing anything wrong — but that discontinuity is exactly what a third-party risk assessment exists to surface before the connection is made.

Financial

Signal & Substance

Do the numbers support the narrative? Trajectory, headcount, beneficial ownership chains — read as risk context for the security decision. The deliverable is well-formed questions a decision-maker can act on, not verdicts.

Most requirements sit cleanly inside one lens at scoping, and the lens is fixed there. When early collection indicates the requirement genuinely spans a second lens, that triggers a scope conversation — a re-tasking decision made with the client, never a silent expansion of collection.

CHAPTER 05 · SOURCE GRADING

Source Hierarchy & Reliability

Classical intelligence practice grades every source for reliability and every claim for credibility — separately. We hold to that discipline. Collection is tasked outward from most authoritative and least contested to most expensive and most contested, and every item in the working layer carries its source grade with it:

  1. Primary records — court filings, regulatory disclosures, official gazettes, financial filings, public records.
  2. Structured secondary — reputable aggregators, archived snapshots of official sources.
  3. Platform-native — public profiles, forums, code repositories, image and video platforms.
  4. Unstructured residue — cached pages, archival fragments, historical technical artifacts.
  5. Human-adjacent — conversations, inferences drawn from network behavior and association patterns.

The Same Source, Tasked Four Ways

To illustrate why grading attaches to the source and analysis attaches to the lens: a single web-archival source, queried against the same estate, satisfies four different intelligence requirements depending on the active lens:

Technical

Tasked for legacy attack surface: forgotten infrastructure, retired admin paths, and subdomains that were never decommissioned.

Human

Tasked for historical workforce exposure — the staff-page and directory data that fuels phishing pretexts today.

Organizational

Tasked for narrative discontinuity — what did this vendor claim to be three years ago, and does the infrastructure agree?

Financial

Tasked for divergence between financial trajectory and the pivots the public narrative has gone through.

Same source. Same query. Four different intelligence requirements satisfied. This is why CANINE is built around lenses, not around data sources.

CHAPTER 06 · STRUCTURED ANALYSIS

Analytic Tradecraft & Calibrated Confidence

Corroborated collection is still not an assessment. Assessment is what happens when the analyst asks, for each piece of evidence: which hypotheses does this make more or less likely, and by how much?

The platform enforces the structured analytic techniques the intelligence community standardised for exactly this: Analysis of Competing Hypotheses to weigh explanations against each other rather than confirming the first one. Key Assumptions Checks to identify what, if wrong, would collapse an assessment. Devil's advocacy — arguing the opposing case before committing to the leading one. And timeline reconstruction, because most incidents and exposures clarify dramatically once events are plotted in order on a single axis.

VERIFICATION

An Indicator Is Not a Finding

An indicator is not a finding until it has been independently corroborated. Every claim — including the analyst's own prior notes — is provisional until two independent sources agree, one primary source is supported by a reproducible artifact, or the product explicitly declares the claim single-sourced. This is the same convergence test that governs processing, applied a second time at the assessment layer.

Every assessment ships in calibrated confidence language, defined in the product itself so the reader is never guessing: assessed with high confidence / moderate confidence / low confidence, with the sourcing criteria behind each level stated. "Likely" and "probably" without a scale behind them are not useful to a decision-maker.

CHAPTER 07 · RULES OF ENGAGEMENT

Collection Boundaries, Enforced in the Platform

Rules of engagement are written before collection begins, and the platform enforces them at the tasking layer. We do not access material we are not authorized to access, regardless of whether it is technically reachable. "Publicly available" is not the same as "lawful to collect," and both differ from "appropriate to use against this requirement."

Collection is lawful, proportionate, and minimised to the requirement: what is not needed to answer the question is not collected, and what is collected is not retained beyond the engagement.

Every assessment in our products is something we would defend in a room where the organisation concerned was present. Speculation dressed as assessment, detail beyond what the requirement demands, and material that would compromise sources and methods do not ship.

The Financial lens has an explicit stop line: it stops where the question becomes "is this fraud?" — at which point a regulated forensic accountant or an investigator with formal legal authority takes over. Up to that line, the doctrine does real work. Past it, we hand over, and we say so in the product.

CHAPTER 08 · DISSEMINATION

The Intelligence Product — and Why the Cycle Became Software

Dissemination is the discipline most operations neglect. An assessment that cannot be interrogated is not finished intelligence. Every CANINE product is briefing-grade by construction: every claim resolves to its primary source in two clicks or fewer, every assessment carries its confidence level and its sourcing criteria, and every known collection gap is declared — so the decision-maker knows exactly what is assessed, what is assumed, and what is unknown.

CANINE exists because running this cycle by hand was costing time on every engagement — tabs, re-run queries, manually connecting findings the data already agreed on. So the doctrine was encoded. The intelligence cycle is the platform's workflow. The convergence test is automated by the CANINE Engine, which refuses to promote an assumption without two or more independent sources. The source hierarchy drives collection prioritisation. The rules of engagement are enforced at the tasking layer. And the privacy-first architecture — designed so that personally identifiable information stays on the analyst's machine — was non-negotiable from day one, because the boundaries are not a feature added later. They are the foundation.

The result is a platform where the doctrine does not live in a document the analyst reads once. It lives in every tasking decision, every promotion the engine allows or refuses, every product generated. The tool runs the cycle the way a disciplined intelligence cell runs it — because that is what it was built from.