RedBlue Goes Live
I published the first RedBlue dashboard and made the loop from external visibility to defensive action visible.
Platform milestone
I published the first RedBlue dashboard at redblue.auvalabs.com. It made the platform direction visible even though the modules were at different stages of maturity.
The core idea is a closed operational loop:
- understand the authorised external attack surface;
- build threat context from evidence;
- measure detection coverage against relevant behaviour;
- investigate gaps and coordinate response;
- feed the result back into the environment profile.
ThreatWatch connection
ThreatWatch supplies current public threat context to the detection model. RedBlue adds organisation-specific scope and operational workflow.
The public milestone did not change the evidence standard. Mock, developing, and production-backed data must remain clearly distinguishable as more integrations move into service.