Content Fingerprinting and Defensive Mapping
I replaced headline matching with content fingerprints and used D3FEND to make defensive coverage less vague.
ThreatWatch
I replaced title-only duplicate detection with content fingerprints. Grouping improved when several outlets covered the same event with different headlines, although vendor boilerplate still required careful tuning.
The change confirmed that the useful unit in threat intelligence is not an individual article. It is an evidence-backed event or finding that can be traced to its sources.
Defensive mapping
MITRE D3FEND adds a defensive vocabulary alongside ATT&CK. It helps distinguish between a detection rule, a broader countermeasure, and whether either is actually deployed.
That distinction shaped the coverage model: represent campaigns as sequences of adversary techniques, link each technique to relevant telemetry and controls, and score the remaining gap. ThreatWatch can then supply current campaign context without becoming the authority for unsupported attribution.