← build journal
Entry 2222 March 2026

RedBlue Goes Live

I published the first RedBlue dashboard and made the loop from external visibility to defensive action visible.

RedBlueSecurity OperationsDetection Engineering

Platform milestone

I published the first RedBlue dashboard at redblue.auvalabs.com. It made the platform direction visible even though the modules were at different stages of maturity.

The core idea is a closed operational loop:

  1. understand the authorised external attack surface;
  2. build threat context from evidence;
  3. measure detection coverage against relevant behaviour;
  4. investigate gaps and coordinate response;
  5. feed the result back into the environment profile.

ThreatWatch connection

ThreatWatch supplies current public threat context to the detection model. RedBlue adds organisation-specific scope and operational workflow.

The public milestone did not change the evidence standard. Mock, developing, and production-backed data must remain clearly distinguishable as more integrations move into service.