01

Collect source material

Configured public sources are retrieved and assigned source identifiers. Collection does not establish that a claim is correct, independent, current, or unique.

02

Preserve provenance

Available source URLs, publisher labels, publication times, retrieval times, and stable record identifiers remain attached so readers can inspect the underlying evidence.

03

Add structure carefully

Records can gain normalized tags, CVE mentions, summaries, or predicted ATT&CK relationships. These fields organize evidence; they do not independently verify it.

04

Publish the available snapshot

Each environment presents its own dated records. Missing fields and unavailable datasets remain visible as limitations rather than being replaced by synthetic claims.

Interpretation guide

Evidence labels

Source record
One row or item from a configured source. It is not necessarily one incident.
Enriched record
Additional machine-generated structure or summary is present and can be incomplete or wrong.
Predicted mapping
A Baitaphish association, not an official MITRE ATT&CK assertion.
Limits

What the method cannot establish

  • Collection volume does not measure threat prevalence, business impact, or risk.
  • Repeated records do not establish independent corroboration.
  • Source and enrichment timestamps describe different events and can be incomplete.
  • Curated incidents and research are selective, not statistically representative.
  • Operational decisions require primary-source review and environment-specific judgment.

← Back to About