Company
Dendrite Update: September 13, 2026
An update on Dendrite's correlation engine, expanded data sources, delivery methods, early-adopter program, and plans for the remainder of 2026.
Dendrite has changed considerably over the past few months. While our core datasets complete their final cloud propagation and correlation processes, I’ve been using the additional time to bring several post-launch roadmap items forward. At the same time, our on-prem infrastructure has scaled to roughly three times its early-July capacity as we work through historical backfill and current production data.
It’s been a while since I’ve published an update, and that’s on me—but I plan to change that going forward. Regardless, I’m excited to share that Dendrite is on track to onboard our first clients during September and October. In this post, we’ll briefly cover enhancements to the core technologies, updates to data sources and delivery methods, the types of partners we hope to work with initially, and some of the questions I’ve received through our various contact channels.
There is much to share from the past few months, but I’ll do my best to keep this a short read.
The goal behind all of this remains the same: rather than forcing analysts and security teams to manually connect isolated intelligence feeds, Dendrite delivers proprietary data with many of those relationships already established. Much of the work described below—whether it involves new data sources, correlation architecture, or delivery methods—is ultimately aimed at making those connections deeper, faster, and easier to consume for agentic AI security solutions.
Redesigned Correlation Engine
As some of you may have read in my posts on X around DEF CON 34, I recently redesigned the correlation engine near the heart of the platform to accommodate a more distributed data-ingestion and correlation model. This was necessary mainly because of the massive increase in data volume after scaling our hybrid infrastructure, but also to streamline future scalability.
Beyond the performance improvements, the redesigned engine substantially expands the depth of Dendrite’s correlation model. It now supports more than 700 distinct correlation paths across our approximately 20 primary data sources—a roughly 15% increase over the previous model, which produced approximately 3.2 trillion correlations.
Aside from the obvious reason for doing this—which is that I think it’s cool, and I’m unapologetically a data maximalist—the practical and operational benefits are significant. The expanded model enables higher-fidelity joins, exposes relationships that were previously difficult or impossible to identify, and further reduces the analytical workload for security teams. It also provides greater temporal context for security agents and other systems consuming derivative products built from the ingested data sources.
That said, the architectural improvements extend beyond correlation depth. Increased efficiency allows newly created records—often represented as “nodes” within the Graphical Data Explorer—to be processed, joined, and made available more rapidly as they enter the Dendrite fabric.
Perhaps most importantly for the long term, the correlation engine is now significantly more modular. This will enable new data sources to be integrated with far less engineering overhead, while the same architecture makes it easier to adapt Dendrite’s data and correlation capabilities to customer environments and integration requirements.
Current State of the Redesign
Believe it or not, building and deploying a distributed system that correlates dozens—often hundreds—of data points across several hundred billion records turned into a multi-week project. With that said, the redesign has been successfully deployed and integrated into the Dendrite fabric. I look forward to building demonstration videos with it and receiving everyone’s feedback.
Changes to Data Sources
Final propagation of our raw data sources is taking longer than I expected, so I’ve used the additional time to move several post-launch roadmap items forward. Each item was selected based on the value it can deliver to clients once integrated into the full Dendrite fabric, and each will be available from day one.
Cryptocurrency Data
Over the past couple of weeks, I’ve substantially increased the depth and fidelity of our cryptocurrency data offering to what I’m calling “near-AML quality.” While it is not yet the definitive source for anti-money laundering analysis, these cryptocurrency data points should provide strong depth and historical context for a wide variety of defensive and analytical use cases.
These enhancements extend analysis well beyond standard cryptocurrency transaction activity to include address activity summaries, transaction-participation relationships, dormant-address activation and activity, a wide range of traceable event evidence, and much more. I’ll be working through a series of use-case scenarios in the near future to demonstrate how this data connects with infrastructure rentals and illicit financing.
Expanded Surface-Web Context
Through its activities on the dark web, our Void Runner pipeline collects a wide range of surface-web links, resources, contact methods, and other information. This has proven effective in mapping how dark-web resources point to deep- and surface-web resources, and vice versa. We recently added capabilities that enable analysts and AI systems to examine this intersection natively within Dendrite data sources.
The applications supporting this pipeline are already in production, backfilling historical surface-web connections while keeping pace with newly collected data. I will publish more specific numbers on this before launch.
Explorator Data
The Command and Control (C2) discovery pipeline, also known as Explorator, has undergone substantial vertical and horizontal scaling since the end of July. Peripheral processes now provide substantially greater data depth and fidelity, while added speed improves data freshness. Together, these changes give analysts, agents, and defensive systems greater clarity into the internet’s malicious infrastructure and improve our ability to map infrastructure to groups, campaigns, transactions, and ongoing—or potentially upcoming—events.
Upcoming Releases
Two additional data-source pipelines will enter production-scale testing during the week of September 13, bringing us to seven independent pipelines in total, each with four to six data products. Like the five pipelines in our current offering, these two new sources are entirely developed in-house, available to consumers as both bundled and individual data pipelines, and pre-correlated with all existing records. Early testing has been extremely promising, with more points of correlation—particularly to C2 records—than I initially anticipated.
Changes to Data Delivery Methods
Dendrite currently supports three primary methods of data delivery: the Graphical Data Explorer, available through our Unified Web Platform; a suite of APIs for direct delivery; and the CLI Utility. All three will remain in a state of constant improvement, with plenty of roadmap ahead. Here is a quick look at what we’ve enhanced recently.
Graphical Data Explorer
A great deal of work has gone into how the Graphical Data Explorer ingests, filters, displays, and stores data to reduce the analytical workload for teams using the web interface alongside their SIEM or integrated software suite. Because it provides an excellent visual representation of our data offering—and because I want to identify as many UI flaws as possible—the Data Explorer will likely feature in most of my demonstrations and analysis videos about current events.
I’ve also started developing the “Data Lab” capabilities, available through the same interface. These will enable users to selectively stage and ingest data records before moving them into production environments. A series of export tools is also in development, with the goal of moving data directly from the live Dendrite environment into users’ reports.
CLI Utility
The FOSS and Hack The Box fanatic in me loves the CLI Utility, and I think many individual users and small teams will love it too—or at least I’m determined to make it a familiar interface they’ll enjoy using. Admittedly, it has taken a back seat to enterprise APIs, connectors, and the web portal, but its current state is close to launch-ready, making a full Q4 2026 release possible. Early feedback suggests the CLI may appeal to a smaller audience than our APIs, connectors, and web platform, so those enterprise delivery methods are receiving more engineering attention ahead of launch.
Partners and Early Adopters
We remain on track to begin serving data and onboarding our first customers across September and October, and the support I’ve received has been nothing short of incredible. Over the past several months, I’ve received many questions about restrictions for early clients, data availability, and partner programs, so these topics are worth a high-level overview.
Regarding data access and availability, all data is offered both bundled and à la carte on a pipeline basis—for example, Void Runner dark-web data—and includes all data sources within that pipeline. Our API and web-portal functions will automatically grant access to the datasets an organization has selected, as well as their correlations to data types within the scope of that account. Because of the nature of some Dendrite datasets, organizations will undergo a basic customer-verification and due-diligence process during contracting, but there will be no additional restrictions for those that complete this phase. The same will be true for researchers seeking individual or small-team accounts, although these registrations will remain invite-only until we can develop a public-signup data product.
Partners are another exciting topic, and I’m extremely grateful to all the value-added resellers, managed security service providers, and other groups that have reached out for conversations and brainstorming sessions. For the first 6–12 months, our partnership efforts will focus on early adopters and what we’re calling “development partners”—generally, organizations with a long-term commercial interest in our data products that are willing to provide technical feedback. Ideally, these partners would also be willing to work with us on at least one case study in the first year if our data sources deliver tangible benefits in their area of focus. Development partners will receive a significant discount from our early-adopter pricing, as well as preferential long-term pricing.
During that same period, we’re also looking to partner with foundations and nonprofits whose missions could benefit from access to Dendrite. We will donate API and web-platform access to multiple users at qualifying foundations at no cost. If you are part of one of these organizations, please reach out.
The Path Forward: Closing Out 2026
For the remainder of the year, Dendrite will be highly focused on scaling our hybrid infrastructure. Based on the infrastructure changes currently planned, I expect daily record creation across our five production data categories to increase by at least four times, while leaving sufficient headroom for the two new pipelines entering production at the same scale.
Beyond infrastructure scaling, the remainder of 2026 will include implementing a long list of roadmap capabilities focused on dataset diversification and increased fidelity across existing sources. That work will also include continued enrichment of our AI datasets and expansion of their delivery methods, including managed services.
Partners and employees—both full-time and contract—will also play a major role in Dendrite’s development this year as we expand our software-development and platform-administration capabilities. Growing the team will become increasingly important through the remainder of the year, particularly across those two areas. I expect to publish several roles directly through the Dendrite website and share them through our social channels.
If you’re interested in becoming an early customer, development partner, research user, or nonprofit partner, please reach out. I’m also planning several more technical posts and demonstration videos ahead of launch. Assuming the final propagation work continues on schedule, we’ll begin onboarding Dendrite’s first customers and partners over the next few weeks.
