← build journal
Entry 1622 February 2026

ThreatWatch Feed Audit Planning

The source audit I wanted for ThreatWatch: freshness, reliability, evidence, duplication, and genuinely unique signal.

ThreatWatchThreat IntelligencePlanning

Reading notes

In recent reporting on business email compromise and unconventional command channels, I found behaviour more useful than short-lived indicators. Infrastructure changes quickly, while recurring tradecraft can remain useful for detection and investigation.

ThreatWatch audit

The planned feed audit would evaluate each source by freshness, reliability, evidence quality, duplication, and unique contribution. The purpose was not to maximise source count. It was to understand which sources consistently improve the briefing.

This also required separating a source that reported no new activity from one that failed to collect. Reliable health information is part of intelligence quality, not merely an operational concern.