RedBlue Integration and CTI Signal Density
The first RedBlue data flow worked, and ThreatWatch made the case for measuring unique signal rather than source count.
RedBlue
I connected controlled security events to detection coverage in the first cross-module data flow. External asset findings also began feeding the environment profile used by the coverage model.
The architecture works best when each module owns a clear responsibility and exchanges typed evidence rather than internal assumptions.
ThreatWatch
Adding sources eventually produces diminishing returns. New feeds often repeat the same upstream reporting, so raw source count is a poor measure of intelligence quality.
A better measure is signal density: how often a source contributes timely, well-supported information that would otherwise be missed. This became the basis for pruning low-value sources and prioritising reliability work on the sources that matter.