Capability architecture
Hunt from a testable hypothesis, not a keyword list.
ThreatCanary combines exposure graph context and validation evidence to investigate whether a technique or condition is present and usable.
01Why it matters
- Analysts need a way to proactively explore risk, not only consume findings.
- Graph queries reveal patterns that lists hide.
- Hunting becomes more powerful when it includes exposure, APIs, identity and validation state.
02ThreatCanary approach
- Provide graph query patterns, saved hunts and visual exploration.
- Search by asset, API, tag, owner, vulnerability, data type, confidence and time.
- Turn interesting observations into hypotheses, findings or reports.
03What it validates or reveals
- Suspicious patterns.
- Related assets and APIs.
- Candidate attack paths for validation.
04Evidence produced
- Hunt hypothesis, query and affected graph nodes.
- Supporting and contradictory evidence.
- Validated outcome and next investigative action.