Threat Triage and Pipeline Reliability
Why I put collection reliability ahead of more feeds, and exposure context ahead of raw vulnerability severity.
ThreatWatch
I was still losing full-text evidence to collection failures. The immediate priority became better fallback behaviour and clearer source health, not more feeds.
Vulnerability triage also reinforced that severity alone is insufficient. Exploitation evidence, exposure, affected environment, and remediation status all influence priority.
RedBlue
RedBlue should carry those distinctions into operational views. A high-severity vulnerability is not automatically the highest organisational risk, and an external finding should not trigger direct action without authorised scope and supporting evidence.
I want the output to be a traceable decision: what was observed, why it matters here, how confident the system is, and what the analyst can verify next.