{
  "schemaVersion": 1,
  "recordType": "sanitised-production-snapshot",
  "source": {
    "huntsApi": "https://threatwatch.auvalabs.com/api/v1/hunts",
    "healthApi": "https://threatwatch.auvalabs.com/api/v1/health",
    "implementation": "https://github.com/AuvaLabs/threatwatch/blob/4cb1650/modules/hunt_engine.py",
    "tests": "https://github.com/AuvaLabs/threatwatch/blob/4cb1650/tests/test_hunt_engine.py"
  },
  "references": {
    "mitreAttack": "https://attack.mitre.org/",
    "cisaKev": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog"
  },
  "snapshot": {
    "apiGeneratedAt": "2026-10-11T11:10:43.827487+00:00",
    "recordedDate": "2026-10-11",
    "deployedRevision": "4cb1650cbc090cb0c13a2abf6d7388e67f138614",
    "candidateCount": 33,
    "qualifiedCount": 1,
    "developingLeadCount": 32
  },
  "qualifiedEvidence": {
    "reportCount": 8,
    "publisherCount": 8,
    "actionableObservableCount": 1,
    "attackTechniqueCount": 3,
    "readinessScore": 100,
    "cisaKev": true
  },
  "limitations": [
    "This record preserves aggregate values, not raw observables or source reports.",
    "It describes one production response and is not a longitudinal measurement.",
    "Qualification does not prove compromise or applicability in a reader's environment."
  ]
}
