Modelling the Detection Lifecycle
I turned the coverage sketches into a model that separates available rules from detections an environment can actually run.
Coverage model
I moved the detection lifecycle from sketches into a working schema. Campaigns are represented as ordered techniques. Techniques link to detection rules, required telemetry, and relevant defensive measures.
The key decision was to score deployability separately from rule availability. A rule should not improve practical coverage if its log source is absent or unreliable.
Project direction
ThreatWatch had a functioning collection and briefing pipeline, with analysis quality as the main constraint. The coverage model had enough structure to begin testing against real campaign data.
These projects were converging on the same objective: translate threat information into defensible operational decisions without overstating confidence.