← build journal
Entry 94 January 2026

Detection Lifecycle Implementation Begins

I put the campaign model into code while keeping ThreatWatch analysis quality as the parallel constraint.

Detection EngineeringATT&CKSigmaThreatWatch

Detection model

I began with a small, explicit model: campaigns contain ordered ATT&CK techniques, techniques link to Sigma rules, and rules declare the telemetry they require.

The first gap output distinguishes between a rule existing and a rule being deployable in a given environment. That prevents a large rule library from creating a false sense of coverage.

ThreatWatch

ThreatWatch collection was stable enough for the focus to move towards quality. The next improvements were source freshness, visible failures, evidence-aware classification, and better handling of repeated reporting.

I am keeping the same rule across both projects: accuracy over volume, visible uncertainty, and deterministic evidence as the authority.