D3FEND Mapping and the First Coverage Output
Adding D3FEND gave me the first honest view of which campaign stages had rules, controls, telemetry, or nothing.
Defensive mapping
I used D3FEND to describe controls that sit alongside rule-based detection. Adding those mappings made the model more honest: a technique may be addressed by telemetry, a preventive control, both, or neither.
The first campaign-level output grouped coverage by stage and highlighted a familiar pattern. Execution activity often has mature endpoint detections, while initial access and encrypted command traffic can remain difficult to observe with standard telemetry.
ThreatWatch
ThreatWatch source health became visible instead of failing silently. That is a small implementation change with a large analytical benefit because an empty feed and a failed feed no longer look the same.
The next step was to bring campaign behaviour, not only short-lived indicators, into the intelligence model.