Published research10 articles
Field note archive

Earlier build notes remain available for context. They are historical records, not current research claims.

Page 1 of 3
Entry 2726 April 2026

ThreatWatch Evidence Quality

Why incomplete source material should lower confidence, and where I draw the evidence boundary between ThreatWatch and RedBlue.

Entry 2619 April 2026

Evidence-Based Vulnerability Triage

I stopped asking severity to do all the work and added exploitation evidence, exposure, and authoritative catalogues.

Entry 2512 April 2026

AI Security and Changing Threat Economics

Automated vulnerability research is moving quickly. I am more interested in adaptable evidence pipelines than precise forecasts.

Entry 245 April 2026

Threat Triage and Pipeline Reliability

Why I put collection reliability ahead of more feeds, and exposure context ahead of raw vulnerability severity.

Entry 2327 March 2026

Connecting RedBlue and ThreatWatch

Connecting RedBlue to real evidence exposed the places where enrichment ends and analyst judgement must begin.

Entry 2222 March 2026

RedBlue Goes Live

I published the first RedBlue dashboard and made the loop from external visibility to defensive action visible.

Entry 2115 March 2026

RedBlue Integration and CTI Signal Density

The first RedBlue data flow worked, and ThreatWatch made the case for measuring unique signal rather than source count.

Entry 2014 March 2026

ThreatWatch Deduplication and RedBlue Data

I tightened duplicate grouping in ThreatWatch and drew a firmer evidence boundary for what RedBlue can consume.

Entry 198 March 2026

ThreatWatch Feed Freshness

A reachable feed can still be stale. I made freshness visible so old data no longer looked current.

Entry 187 March 2026

RedBlue Dashboard Early Work

The first RedBlue dashboard showed me where the modules connected and where the evidence contracts were still weak.