← build journal
Entry 1118 January 2026

D3FEND Mapping and the First Coverage Output

Adding D3FEND gave me the first honest view of which campaign stages had rules, controls, telemetry, or nothing.

Detection EngineeringD3FENDATT&CKThreatWatch

Defensive mapping

I used D3FEND to describe controls that sit alongside rule-based detection. Adding those mappings made the model more honest: a technique may be addressed by telemetry, a preventive control, both, or neither.

The first campaign-level output grouped coverage by stage and highlighted a familiar pattern. Execution activity often has mature endpoint detections, while initial access and encrypted command traffic can remain difficult to observe with standard telemetry.

ThreatWatch

ThreatWatch source health became visible instead of failing silently. That is a small implementation change with a large analytical benefit because an empty feed and a failed feed no longer look the same.

The next step was to bring campaign behaviour, not only short-lived indicators, into the intelligence model.