Starting the Research Journal
Why I started ThreatWatch narrowly, and the telemetry question that shaped the detection work beside it.
ThreatWatch
I started ThreatWatch with a deliberately narrow plan: collect useful public cyber threat reporting, remove duplicate coverage, and produce a briefing worth reading. I chose a simple local data model because source quality and analysis accuracy mattered more than scale.
Detection coverage
Reading across MITRE ATT&CK and detection engineering research highlighted a recurring gap. A rule can exist for a technique while remaining unusable because the required telemetry is unavailable, too noisy, or too expensive to retain.
That distinction between theoretical and practical coverage became the basis for a second line of work. Instead of counting rules, the goal is to model what can be detected across a full campaign and identify where visibility breaks down.
The two ideas connect naturally: ThreatWatch provides current threat context, while coverage analysis turns that context into defensive priorities.