ThreatWatch Feed Audit Planning
The source audit I wanted for ThreatWatch: freshness, reliability, evidence, duplication, and genuinely unique signal.
Reading notes
In recent reporting on business email compromise and unconventional command channels, I found behaviour more useful than short-lived indicators. Infrastructure changes quickly, while recurring tradecraft can remain useful for detection and investigation.
ThreatWatch audit
The planned feed audit would evaluate each source by freshness, reliability, evidence quality, duplication, and unique contribution. The purpose was not to maximise source count. It was to understand which sources consistently improve the briefing.
This also required separating a source that reported no new activity from one that failed to collect. Reliable health information is part of intelligence quality, not merely an operational concern.