← build journal
Entry 2115 March 2026

RedBlue Integration and CTI Signal Density

The first RedBlue data flow worked, and ThreatWatch made the case for measuring unique signal rather than source count.

RedBlueThreatWatchThreat Intelligence

RedBlue

I connected controlled security events to detection coverage in the first cross-module data flow. External asset findings also began feeding the environment profile used by the coverage model.

The architecture works best when each module owns a clear responsibility and exchanges typed evidence rather than internal assumptions.

ThreatWatch

Adding sources eventually produces diminishing returns. New feeds often repeat the same upstream reporting, so raw source count is a poor measure of intelligence quality.

A better measure is signal density: how often a source contributes timely, well-supported information that would otherwise be missed. This became the basis for pruning low-value sources and prioritising reliability work on the sources that matter.