← build journal
Entry 113 November 2025

Starting the Research Journal

Why I started ThreatWatch narrowly, and the telemetry question that shaped the detection work beside it.

ThreatWatchDetection EngineeringPlanning

ThreatWatch

I started ThreatWatch with a deliberately narrow plan: collect useful public cyber threat reporting, remove duplicate coverage, and produce a briefing worth reading. I chose a simple local data model because source quality and analysis accuracy mattered more than scale.

Detection coverage

Reading across MITRE ATT&CK and detection engineering research highlighted a recurring gap. A rule can exist for a technique while remaining unusable because the required telemetry is unavailable, too noisy, or too expensive to retain.

That distinction between theoretical and practical coverage became the basis for a second line of work. Instead of counting rules, the goal is to model what can be detected across a full campaign and identify where visibility breaks down.

The two ideas connect naturally: ThreatWatch provides current threat context, while coverage analysis turns that context into defensive priorities.