Capability architecture
From vulnerability signal to researcher-grade testing intelligence.
ThreatCanary does more than aggregate CVEs. It investigates the evidence behind a vulnerability, reasons about how it could affect the target and converts that research into controlled, repeatable validation.
01Start with a research question
- Begin with a discovered product and version, a published CVE, an unexpected behaviour or a suspected novel weakness.
- Ask what affects this exact technology, which conditions are required and how the issue can be demonstrated safely.
- Use live target context to focus the investigation instead of treating every vulnerability record as equally relevant.
02Investigate like a security researcher
- Gather official advisories, vendor disclosures, technical write-ups, exploit code, proof-of-concept material and patch analysis.
- Normalise and deduplicate fragmented research while preserving source provenance.
- Connect vulnerabilities to products, affected versions, weakness classes, exploit prerequisites and related research.
03Research beyond the English-language web
- Discover emerging security research published in Chinese, Russian and other languages that English-speaking teams can struggle to monitor continuously.
- Translate technical meaning, vulnerability mechanics and testing methodology—not merely the words on the page.
- Preserve the original source, translated interpretation and confidence so researchers can verify what the intelligence means before using it.
04Build a target-specific test plan
- Extract affected-version logic, preconditions, attack primitives, detection techniques and safe validation methods.
- Turn conflicting or incomplete research into explicit hypotheses that can be tested against the authorised target.
- Rank the next research and testing steps by relevance, confidence, safety and potential impact.
05Move from research to validation
- Supply offensive agents with the context and methodology needed to test the target—not merely a CVE label.
- When no suitable test exists, pass clear capability requirements to Weapons Foundry and tool-adaptation workflows.
- Capture the request, execution path, result and supporting evidence so the conclusion can be reviewed and reproduced.
06Convert manual insight into reusable capability
- Retain successful testing methods, exploit knowledge and supporting research as structured, versioned intelligence.
- Link each capability back to the hypothesis, target conditions, source material and evidence that justified it.
- Reuse proven research across future assessments so the platform becomes more capable with every validated outcome.
07Keep researchers in control
- Automate collection, correlation, synthesis and routine test preparation while preserving expert review points.
- Escalate ambiguous, sensitive or higher-impact actions through approval workflows before execution.
- Give researchers a traceable workspace for deciding what to test, why it matters and what the evidence proves.
08Research outputs
- Target-specific vulnerability briefs with affected-version and prerequisite analysis.
- Prioritised hypotheses, testing methodologies, proof-of-concept references and patch-diff context.
- Validated findings with reproducible evidence and clear confidence.
- Reusable offensive capabilities that preserve provenance, safety controls and operational history.