← build journal
Entry 327 November 2025

Content Fingerprinting and Defensive Mapping

I replaced headline matching with content fingerprints and used D3FEND to make defensive coverage less vague.

ThreatWatchD3FENDDetection Engineering

ThreatWatch

I replaced title-only duplicate detection with content fingerprints. Grouping improved when several outlets covered the same event with different headlines, although vendor boilerplate still required careful tuning.

The change confirmed that the useful unit in threat intelligence is not an individual article. It is an evidence-backed event or finding that can be traced to its sources.

Defensive mapping

MITRE D3FEND adds a defensive vocabulary alongside ATT&CK. It helps distinguish between a detection rule, a broader countermeasure, and whether either is actually deployed.

That distinction shaped the coverage model: represent campaigns as sequences of adversary techniques, link each technique to relevant telemetry and controls, and score the remaining gap. ThreatWatch can then supply current campaign context without becoming the authority for unsupported attribution.