Build Journal
I now publish every two weeks. I choose one problem from ThreatWatch or RedBlue and write down what changed my mind: the constraint, the decision, the evidence, and what I would do differently. No release notes, no filler.
Campaign-Level Detection Coverage
Why I moved away from flat rule counts and towards campaign paths, telemetry, and the gaps between them.
Modelling the Detection Lifecycle
I turned the coverage sketches into a model that separates available rules from detections an environment can actually run.
ThreatWatch Expansion and Analysis Guardrails
Adding sources was easy. Keeping automated analysis tied to evidence became the more important constraint.
Authorised Simulation and Detection Lessons
What an end-to-end lab simulation taught me about scope, evidence collection, and useful reporting.
Content Fingerprinting and Defensive Mapping
I replaced headline matching with content fingerprints and used D3FEND to make defensive coverage less vague.
ThreatWatch First Run and the Signal Problem
The first ThreatWatch run collected plenty of reporting. Finding the part worth reading was the harder problem.
Starting the Research Journal
Why I started ThreatWatch narrowly, and the telemetry question that shaped the detection work beside it.