Detection Lifecycle Implementation Begins
I put the campaign model into code while keeping ThreatWatch analysis quality as the parallel constraint.
Detection model
I began with a small, explicit model: campaigns contain ordered ATT&CK techniques, techniques link to Sigma rules, and rules declare the telemetry they require.
The first gap output distinguishes between a rule existing and a rule being deployable in a given environment. That prevents a large rule library from creating a false sense of coverage.
ThreatWatch
ThreatWatch collection was stable enough for the focus to move towards quality. The next improvements were source freshness, visible failures, evidence-aware classification, and better handling of repeated reporting.
I am keeping the same rule across both projects: accuracy over volume, visible uncertainty, and deterministic evidence as the authority.