Tier-1 analysts never read your threat-intel enrichment panel - how do you fix the delivery?
answer
- intel outside the chair does not exist
- a field on the alert, not a panel
- source, first seen, reason, window
- a bare score moves no verdict
- sample closed cases, not click counts
basics
~20 sMove the intel into surfaces analysts already work in: the alert's own fields, the endpoint tool's match list, the case record. Make each hit state its source, first-seen date and reason, then sample closed cases for verdicts that changed.
solid answer
~50 sIntel that requires an analyst to leave their chair does not exist. I stop treating the panel as the delivery mechanism and push matches into the places the work already happens: a matched-intel field on the alert record itself so it is visible without scrolling and searchable afterwards, the endpoint tool's own indicator list so the match happens where response actions live, and the case record so the write-up inherits it. Content matters as much as position - a bare score of 87 moves nothing, while source, first-seen date, stated reason and validity window let an analyst weigh it in seconds. I also watch enrichment precision: if it decorates every alert, including hits on CDN addresses, it becomes furniture and gets ignored regardless of placement. The acceptance test is not adoption; it is a sampled review of closed cases showing verdicts that came out differently.
go deeper
Know that intelligence only counts when it reaches the person deciding, and be able to say what you would want to see beside an alert to make a listed domain useful.
Explain the mechanics of delivery - enrichment at alert-creation time, a searchable field rather than a panel, indicator lists pushed into the endpoint tooling - and why timing matters as much as placement.
Show the operating judgment: managing the enrichment's own precision so it stays meaningful, and proving effect by sampling closed cases for verdicts that came out differently.
Own where the boundary sits between third-party curation and action in your estate, and be prepared to argue why automatic containment on an external list is a control you do not fully own.
## The failure is delivery, not intelligence A feed can be excellent and still change nothing, because the last hop - from the intel platform into the moment a human decides - is where most intelligence programmes fail. A tier-1 analyst working a queue has a fixed budget of seconds per alert. Anything that requires opening a second tool, remembering a portal password, or scrolling past the fold competes with that budget and loses. So the design question is never "is this intel good"; it is "where does the analyst's eye already go, and is the intel there". ## The three surfaces worth delivering into **1. The alert record itself.** The strongest placement is a field on the alert, populated at enrichment time, above the fold and adjacent to the artefact it describes. A field, not a panel: it renders in the queue view, it survives export into the case, and it is *searchable* - you can later ask how many alerts carried an intel match, which is the data you need for the measurement conversation. **2. The control the analyst already reaches for.** Pushing an indicator list into the endpoint or identity tooling means the match surfaces where the response actions are, in the same interface where the analyst can look at process ancestry or a session's history. It also means the match happens on artefacts the tool sees, not only on the fields your log pipeline happened to parse. **3. The case record.** Whatever the analyst writes up should inherit the intel automatically - source, artefact, reason - so the next person reading the case understands why the verdict went the way it did without repeating the lookup. What is *not* a delivery surface: a weekly PDF, a portal nobody has credentials for, a Slack channel that scrolls, or a wiki page. Those are reporting, and they reach a different audience for a different purpose. ## Content: what makes a hit move a verdict Placement gets it seen; content makes it useful. A number alone is inert - an analyst cannot reason about "risk 87". Four fields do almost all the work: - **Source**, because analysts learn quickly which of their sources deserve weight; - **First seen**, because a listing from two years ago against today's traffic is a different claim from one made this morning; - **Why it was listed**, in one clause - credential-harvesting page, command-and-control for a named tooling family, scanning infrastructure - because that is what connects to the behaviour in front of them; - **Validity window**, so an expired listing is visibly expired rather than silently authoritative. Add one more thing if you can: whether the artefact is *shared* infrastructure. A hit on an address a hundred of your hosts talk to daily should say so, because that single fact prevents most of the wasted escalations. ## Precision of the enrichment itself If every alert gets decorated, the decoration stops carrying information. Enrichment that fires on public resolver addresses, CDN edges and popular hosting ranges trains analysts to skip it, and once skipped it is skipped even when it matters. Treat the enrichment as having its own precision budget: suppress artefact classes that cannot support a verdict, and prefer marking fewer alerts with a stronger claim. This is a different question from whether an alerting rule pages too often - it is about whether *this decoration* is ever the thing that decides. ## Timing Delivery has a clock as well as a place. If the intel platform ingests nightly while alerts are worked in minutes, the enrichment arrives after the verdict was already written. Matching must happen at alert-creation time, and for the fast-moving artefact classes the feed must be consumed as a stream rather than a daily file. An enrichment that would have been decisive and arrived six hours late is indistinguishable from no enrichment at all. ## Proving it worked Adoption metrics - panel views, clicks - measure attention, not effect. The acceptance test is a sampled review of closed cases: pull a set of investigations that carried an intel match and ask whether the match is cited in the reasoning, and whether the verdict would plausibly have been different without it. What you are hunting for is the nameable case - the one where an analyst escalated in minutes because the landing domain in an ordinary-looking sign-in alert had been carried by one source before the first message was even delivered. One such case, written down with the timeline, is worth more in every subsequent conversation than a year of view counts. ## One caution Resist wiring intel matches straight into automatic severity escalation or automatic containment. The artefact list is curated outside your organisation; anything that mechanically converts a third party's listing into an action in your estate is a lever you do not fully own. Let intel raise a human's attention, and keep the decision to act on your side of the boundary.
- Analysts say the enrichment is now visible but they still ignore it. What is your next move?I look at precision before placement. If the field is populated on most alerts - because it matches CDN edges, public resolvers and popular hosting - then ignoring it is rational behaviour and I should suppress those artefact classes so the field appears rarely and means something when it does. I would also sample cases where it was populated and see whether the reason text was actionable, since an unexplained listing is easy to skip.
- Would you let an intel match automatically raise an alert's severity?Reluctantly and narrowly, if at all. The list is curated outside my organisation, so mechanical escalation hands a third party partial control of my queue, and a mislabelled or stale artefact then reorders analyst attention. I would let it raise attention - ordering, visual weight - and keep the severity decision with a human. If I did automate anything, I would scope it to a small, high-confidence, internally reviewed indicator set.
- How would you demonstrate the enrichment changed an outcome?By naming the case. I sample closed investigations that carried a match, read the analyst's reasoning, and look for verdicts that turned on it - ideally one where the intel arrived ahead of the activity and the analyst escalated faster than the evidence alone would have allowed. A written timeline of one such case carries more weight with the people funding the feed than any adoption metric.
saying these in an interview costs you the question
- Answers with a portal, a weekly PDF or a wiki page
- Delivers a bare risk score with no source or reason
- Measures success by panel views instead of changed verdicts
- Ignores that matching must happen before the verdict is written
- Enriches every alert and wonders why it is ignored
- Wires third-party listings straight into automatic containment