ThreatWatch Deduplication and RedBlue Data
I tightened duplicate grouping in ThreatWatch and drew a firmer evidence boundary for what RedBlue can consume.
ThreatWatch
I moved near-duplicate grouping towards a similarity-based approach that handles syndicated and lightly rewritten coverage more consistently. I still want to preserve distinct evidence, just without letting repeated reporting dominate the briefing.
RedBlue
Detection analysis began using campaign context derived from ThreatWatch. This connected current threat reporting to ATT&CK techniques, telemetry requirements, and defensive coverage.
The integration also exposed a useful boundary. ThreatWatch can propose campaign relationships, but RedBlue should consume only relationships supported by sufficient evidence. Uncertain analysis remains a developing lead rather than an operational conclusion.
This evidence gate is more important than the number of integrations. It keeps both products useful without overstating what automated correlation can prove.