← build journal
Entry 220 November 2025

ThreatWatch First Run and the Signal Problem

The first ThreatWatch run collected plenty of reporting. Finding the part worth reading was the harder problem.

ThreatWatchThreat IntelligenceDetection Engineering

First aggregation cycle

On the first multi-source run, I could collect and store reporting, but title matching was not enough to identify the same story across different publishers.

The next design decision was to compare article content rather than headlines. Relevance also needed to account for novelty and actionability, not only publication time.

Practical detection

A review of community detection rules reinforced the difference between documented coverage and deployable coverage. Many useful rules depend on event sources that must be configured correctly before they produce any value.

The lesson from both areas was the same: more inputs do not automatically create better outcomes. ThreatWatch needs strong evidence, provenance, and filtering. Detection engineering needs telemetry-aware coverage rather than raw rule counts.