<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Nicholai | Build Journal</title><description>Selected narratives from building ThreatWatch and RedBlue, covering context, decisions, evidence, and lessons.</description><link>https://nicholai.me/</link><language>en-gb</language><item><title>ThreatWatch Evidence Quality</title><link>https://nicholai.me/research/week-19-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-19-2026/</guid><description>The latest journal entry focuses on improving evidence quality, collection resilience, and the connection between ThreatWatch findings and RedBlue workflows.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Evidence-Based Vulnerability Triage</title><link>https://nicholai.me/research/week-18-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-18-2026/</guid><description>ThreatWatch continued improving vulnerability prioritisation by combining severity with exploitation evidence and authoritative catalogues.</description><pubDate>Sun, 19 Apr 2026 00:00:00 GMT</pubDate></item><item><title>AI Security and Changing Threat Economics</title><link>https://nicholai.me/research/week-17-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-17-2026/</guid><description>Research into automated vulnerability discovery raised new questions about how quickly defensive priorities may need to adapt.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Threat Triage and Pipeline Reliability</title><link>https://nicholai.me/research/week-16-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-16-2026/</guid><description>Vulnerability prioritisation, ThreatWatch collection reliability, and keeping RedBlue analysis tied to current evidence.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate></item><item><title>Connecting RedBlue and ThreatWatch</title><link>https://nicholai.me/research/week-15-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-15-2026/</guid><description>RedBlue modules began exchanging real evidence, including threat context from ThreatWatch and controlled event data for detection analysis.</description><pubDate>Fri, 27 Mar 2026 00:00:00 GMT</pubDate></item><item><title>RedBlue Goes Live</title><link>https://nicholai.me/research/week-14-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-14-2026/</guid><description>RedBlue reached its first public dashboard milestone, bringing external visibility, threat profiling, detection analysis, and response into one platform direction.</description><pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate></item><item><title>RedBlue Integration and CTI Signal Density</title><link>https://nicholai.me/research/week-13-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-13-2026/</guid><description>The first RedBlue module integrations worked, while ThreatWatch source growth showed why unique signal matters more than feed volume.</description><pubDate>Sun, 15 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ThreatWatch Deduplication and RedBlue Data</title><link>https://nicholai.me/research/week-12-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-12-2026/</guid><description>ThreatWatch improved near-duplicate grouping, and RedBlue began evaluating detection coverage against campaign context derived from threat intelligence.</description><pubDate>Sat, 14 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ThreatWatch Feed Freshness</title><link>https://nicholai.me/research/week-11-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-11-2026/</guid><description>Feed freshness became a visible ThreatWatch quality signal, helping distinguish current intelligence from stale or unavailable reporting.</description><pubDate>Sun, 08 Mar 2026 00:00:00 GMT</pubDate></item><item><title>RedBlue Dashboard Early Work</title><link>https://nicholai.me/research/week-10-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-10-2026/</guid><description>The first RedBlue dashboard prototype made the platform architecture tangible and clarified how threat profiles and detection coverage should connect.</description><pubDate>Sat, 07 Mar 2026 00:00:00 GMT</pubDate></item><item><title>RedBlue Architecture Takes Shape</title><link>https://nicholai.me/research/week-09-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-09-2026/</guid><description>The detection coverage work expanded into RedBlue, a platform connecting attack-surface visibility, threat profiling, detection validation, and response.</description><pubDate>Sun, 01 Mar 2026 00:00:00 GMT</pubDate></item><item><title>ThreatWatch Feed Audit Planning</title><link>https://nicholai.me/research/week-08-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-08-2026/</guid><description>A focused review of threat actor tradecraft and a structured approach to auditing ThreatWatch source health and signal quality.</description><pubDate>Sun, 22 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Indirect Prompt Injection and RAG</title><link>https://nicholai.me/research/week-07-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-07-2026/</guid><description>Indirect prompt injection remains a core risk for systems that retrieve untrusted content and pass it to a language model.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate></item><item><title>ThreatWatch Analysis Quality</title><link>https://nicholai.me/research/week-06-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-06-2026/</guid><description>ThreatWatch shifted from simple keyword ranking towards novelty, freshness, and source health as first-class signals.</description><pubDate>Sun, 08 Feb 2026 00:00:00 GMT</pubDate></item><item><title>Session-Based Phishing and Strong Authentication</title><link>https://nicholai.me/research/week-05-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-05-2026/</guid><description>A controlled review of adversary-in-the-middle phishing reinforced why origin-bound authentication is stronger than reusable codes.</description><pubDate>Sun, 01 Feb 2026 00:00:00 GMT</pubDate></item><item><title>QR Phishing as a Cross-Device Detection Gap</title><link>https://nicholai.me/research/week-04-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-04-2026/</guid><description>Research into QR phishing highlighted how attacks can move activity from managed email systems to personal mobile devices.</description><pubDate>Sun, 25 Jan 2026 00:00:00 GMT</pubDate></item><item><title>D3FEND Mapping and the First Coverage Output</title><link>https://nicholai.me/research/week-03-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-03-2026/</guid><description>D3FEND mappings were added to the detection model, allowing the first campaign-level view of rules, telemetry, controls, and remaining gaps.</description><pubDate>Sun, 18 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Long-Context Model Security</title><link>https://nicholai.me/research/week-02-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-02-2026/</guid><description>A review of many-shot jailbreaking and what long-context attacks mean for systems that use language models in security workflows.</description><pubDate>Sun, 11 Jan 2026 00:00:00 GMT</pubDate></item><item><title>Detection Lifecycle Implementation Begins</title><link>https://nicholai.me/research/week-01-2026/</link><guid isPermaLink="true">https://nicholai.me/research/week-01-2026/</guid><description>The campaign and detection data model moved into implementation, with ThreatWatch analysis quality set as the parallel priority.</description><pubDate>Sun, 04 Jan 2026 00:00:00 GMT</pubDate></item><item><title>First Journal Review and Q1 Direction</title><link>https://nicholai.me/research/week-08-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-08-2025/</guid><description>A concise review of the first seven weeks: ThreatWatch was operational, the detection coverage model had a schema, and the next priority was connecting intelligence to action.</description><pubDate>Sun, 28 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Campaign-Level Detection Coverage</title><link>https://nicholai.me/research/week-07-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-07-2025/</guid><description>A focused review of graph-based detection models and why campaign-level coverage is more useful than isolated technique counts.</description><pubDate>Thu, 25 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Modelling the Detection Lifecycle</title><link>https://nicholai.me/research/week-06-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-06-2025/</guid><description>The detection coverage idea became a concrete data model linking campaigns, ATT&amp;CK techniques, rules, telemetry requirements, and defensive controls.</description><pubDate>Thu, 18 Dec 2025 00:00:00 GMT</pubDate></item><item><title>ThreatWatch Expansion and Analysis Guardrails</title><link>https://nicholai.me/research/week-05-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-05-2025/</guid><description>ThreatWatch expanded its source coverage while research into model security reinforced the need to keep automated analysis evidence-bound.</description><pubDate>Thu, 11 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Authorised Simulation and Detection Lessons</title><link>https://nicholai.me/research/week-04-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-04-2025/</guid><description>A controlled phishing simulation workflow reached an end-to-end lab milestone and exposed useful detection and reporting requirements.</description><pubDate>Thu, 04 Dec 2025 00:00:00 GMT</pubDate></item><item><title>Content Fingerprinting and Defensive Mapping</title><link>https://nicholai.me/research/week-03-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-03-2025/</guid><description>ThreatWatch moved from headline matching to content fingerprints, while D3FEND provided a clearer vocabulary for connecting adversary behaviour to defensive measures.</description><pubDate>Thu, 27 Nov 2025 00:00:00 GMT</pubDate></item><item><title>ThreatWatch First Run and the Signal Problem</title><link>https://nicholai.me/research/week-02-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-02-2025/</guid><description>The first ThreatWatch aggregation cycle made the central challenge clear: collecting feeds is easy, but separating useful intelligence from repeated reporting is not.</description><pubDate>Thu, 20 Nov 2025 00:00:00 GMT</pubDate></item><item><title>Starting the Research Journal</title><link>https://nicholai.me/research/week-01-2025/</link><guid isPermaLink="true">https://nicholai.me/research/week-01-2025/</guid><description>The first architecture notes for ThreatWatch and an early question that still guides the work: how much detection coverage is practical with the telemetry organisations actually have?</description><pubDate>Thu, 13 Nov 2025 00:00:00 GMT</pubDate></item></channel></rss>