ALFACANDEFENCE GROUP
HomeGuardian CloudAI StudioMercanonBlackWingsPartnersTeamContact

Company

ALFACAN DEFENCE GROUP LIMITED

66 Paul Street
London EC2A 4NA
United Kingdom

Products

  • Guardian Cloud
  • ALFACAN Mercanon
  • ALFACAN AI Studio
  • ALFACAN BlackWings

About

  • About Us
  • Our Team
  • Contact

Follow us on social media

Privacy Policy|Terms & Conditions|Refund Policy

© 2026 ALFACAN DEFENCE GROUP. All rights reserved.

Alfacan Defence Group Limited | Company No. 17062207

Registered in England and Wales

OverviewSysadminITDRAI ModelsDoctrineAI StudioTariffs & Billing
Your browser does not support the video tag.

Guardian Cloud · Module

Doctrine

Live · Validated

the knowledge the AI reasons with

Doctrine is a living knowledge base the AI reasons with — not a static rule file. Rules of engagement, playbooks, verified intelligence and the lessons of past incidents, retrieved by meaning and fed into every decision the officers make.

Retrieval is two-stage: an instruction-aware embedder (Qwen3-VL-Embedding-8B, 1024-dim) recalls candidates by intent, and a cross-encoder reranker (Qwen3-VL-Reranker-2B) keeps only the most precise — the model sees the few most relevant pieces, not a keyword dump.

The knowledge is layered and governed: rules of engagement always sit on top, unreviewed entries stay out of live reasoning, and after every incident the outcome is distilled back into doctrine — so each next decision is sharper than the last.

Two-stage semantic retrieval

Recall broadly, then rerank precisely — so the model sees the few most relevant pieces, not a keyword dump.

Retrieval pipeline

Query · intent
1
Embed · Qwen3-VL-Embedding-8B · 1024-dim
2
Rerank · Qwen3-VL-Reranker-2B
3
Top-K → prompt
4

Recall

The instruction-aware 8B embedder finds candidates by meaning, not exact words — so the officer’s intent (“how do I report and contain this attacker”) surfaces the right doctrine.

Rerank

A cross-encoder reranker scores each candidate against the query and keeps only the strongest — precision over volume.

Layered and governed

Not all knowledge is equal. Doctrine is ranked by authority and gated by review.

The authority cascade

Rules of engagement

always injected · top authority

Playbooks

operational procedures

Verified references

trusted intel & vendor guidance

Community knowledge

lowest authority

Higher-authority layers win when guidance conflicts. Unreviewed entries are excluded from live reasoning.

The evolve loop

After an incident, the outcome is distilled into a lesson — held pending until a human approves it, then it becomes active doctrine. Superseded guidance is retired, never silently overwritten.

Debrief → doctrine learns

Incident outcome
1
Distill lesson
2
Pending review
3
Approved → active
4
Sharper decision
5

Knowledge sources

Doctrine is grounded in industry standards and vendor documentation — every entry cites a verifiable source, not an invented rule — and enriched by open threat-intel feeds.

Standards & frameworks

  • ▸MITRE ATT&CK — TTP & group mapping
  • ▸OWASP · CWE — secure-coding
  • ▸CIS Benchmarks — hardening
  • ▸NIST 800-61r2 — incident response

Vendor & detection docs

  • ▸Wazuh — HIDS rules, FIM, indexer
  • ▸Elastic / OpenSearch — SIEM correlation
  • ▸Suricata / ET-Open · ModSecurity CRS
  • ▸auditd · Sysmon-for-Linux · fail2ban / CrowdSec

Open threat-intel feeds — abuse.ch

  • ▸URLhaus · ThreatFox · Feodo Tracker · SSLBL · MalwareBazaar
  • ▸600+ feed entries grouped by malware family
  • ▸Refreshed automatically on a schedule

Curated malware knowledge

  • ▸Linux families: XorDDoS, Kinsing, TeamTNT, Mirai, BPFDoor, Symbiote, miners, webshells, ransomware
  • ▸ClamAV signatures + YARA + behavioural detection, MITRE-mapped

Founding doctrine

  • ▸Rules of engagement — pinned, top layer
  • ▸CIS-hardening & ops playbooks (sysadmin)
  • ▸OWASP / CWE secure-coding patterns (coding)

Three domains, one engine

Sysadmin

Operational playbooks for diagnosis and remediation.

ITDR

Rules of engagement, incident playbooks and threat intel.

Coding

Secure-coding rules and project context for AI Studio.

Validation & test results

The doctrine pipeline was exercised end-to-end against a live embedder on GPU — write, retrieve, learn, govern.

CheckDetailResult
WriteNew entries indexed and made retrievable✅ PASS
Semantic readA query by intent returned exactly the relevant intel at the top✅ PASS
Debrief → doctrineIncident outcome written back as a reviewable lesson✅ PASS
GovernancePending lessons excluded from live reasoning until approved✅ PASS

End-to-end on the live srag-l4 embedder (Qwen3-VL-Embedding-8B + Qwen3-VL-Reranker-2B) over Qdrant — 2026-06-13.