← build journal
Entry 2327 March 2026

Connecting RedBlue and ThreatWatch

Connecting RedBlue to real evidence exposed the places where enrichment ends and analyst judgement must begin.

RedBlueThreatWatchDetection Engineering

Integration progress

I began connecting controlled security events, threat profiles, and detection coverage in one RedBlue workflow. ThreatWatch campaign context could be mapped into the attack model, while enrichment added supporting information to observables.

The integrations also showed where translation is uncertain. Infrastructure relationships do not always map cleanly to a complete ATT&CK technique set. Those gaps need explicit confidence and analyst review rather than hidden assumptions.

ThreatWatch reliability

Collection improvements helped with difficult web sources, but reliability work remained ongoing. The public value is not the collection technique itself. It is whether the final finding has enough evidence, provenance, and freshness to support action.

My priority is still fewer, stronger claims with a visible path back to the source material.