← build journal
Entry 245 April 2026

Threat Triage and Pipeline Reliability

Why I put collection reliability ahead of more feeds, and exposure context ahead of raw vulnerability severity.

ThreatWatchRedBlueVulnerability Management

ThreatWatch

I was still losing full-text evidence to collection failures. The immediate priority became better fallback behaviour and clearer source health, not more feeds.

Vulnerability triage also reinforced that severity alone is insufficient. Exploitation evidence, exposure, affected environment, and remediation status all influence priority.

RedBlue

RedBlue should carry those distinctions into operational views. A high-severity vulnerability is not automatically the highest organisational risk, and an external finding should not trigger direct action without authorised scope and supporting evidence.

I want the output to be a traceable decision: what was observed, why it matters here, how confident the system is, and what the analyst can verify next.