skip to content

Threat Intelligence & OSINT

How a defender produces and consumes intelligence: requirements tied to a decision, collection that does not tip an operator off, clustering without over-claiming, and intel that reaches a control.

on this pageshow

explore

questions

page 1 of 2

Why can't a 1.8-million-indicator threat feed be pushed straight into a proxy block list?

level: juniorimportance: must knowfreq 55%

answer

  1. two costs, not one
  2. the list runs in the traffic path
  3. object groups have entry ceilings
  4. malicious addresses are rarely dedicated
  5. block narrowly, match widely

basics

~20 s

Every entry costs something to evaluate and something to be wrong about. Enforcement lists have size and push limits, and adversary infrastructure usually sits on shared or CDN-fronted addresses that also carry your own business traffic.

solid answer

~40 s

There are two costs, and volume ignores both. The first is match cost: an enforcement point evaluates its list on traffic in the path, and proxy destination lists and firewall object groups have vendor ceilings on entries, plus real compile-and-push time across every region. The second, and the one that hurts, is collateral: adversary infrastructure is mostly rented and mostly shared, so a large share of malicious addresses are shared hosting, CDN edges or big SaaS platforms carrying your payroll or CRM traffic too. So I select. I enforce specific, high-confidence indicators — a URL or a hostname, rarely a bare address, never a prefix — and I send the rest to matching in the SIEM, where being wrong produces an alert an analyst closes rather than an outage nobody can attribute to me.

go deeper

for a junior

Be ready to say that a block list costs both match capacity and collateral damage, and that a feed's size is not evidence of protection. Name the safest indicator types to enforce: URLs and hostnames.

for a middle

Explain where the limits actually bite — entries per object group, compile and distribution time across regions — and how indicator type and confidence drive which entries go inline versus which go to matching.

for a senior

Show a written selection policy: what you enforce, what you refuse to enforce, what stays on a documented allow-list, and how you keep visibility on everything you chose not to block.

for a principal

Own the trade the business is actually making: enforcement buys prevention and buys outage risk in the same purchase, and your team should be able to state in advance which classes of indicator it will ever push into a traffic path.

## Two places an indicator can land An indicator is an artefact somebody observed — an address, a domain, a URL, a file hash. A feed delivers them in bulk, and the important decision is not whether to take them but *where to put them*. A **detection** point matches indicators against records that have already been written: proxy access logs, DNS query logs, flow records, endpoint telemetry. A hit produces an alert, and a human decides what it means. An **enforcement** point sits in the traffic path: a forward proxy's destination or category list, an egress firewall object group, a DNS sinkhole. A hit stops a connection, immediately, with no human in the loop. Bulk-loading a feed into the second kind is the mistake. The question is which small subset of indicators earns a place there. ## Cost one: match cost and list mechanics An inline control evaluates its lists against traffic, so list size is not free. Concretely: - Firewall object groups and access lists have vendor-specific ceilings on entries, and large ones consume constrained hardware matching resources; you can hit the ceiling and have the push simply fail. - Proxy destination lists must be compiled and distributed to every node in every region; a very large list turns a routine push into a slow, heavyweight operation. - A list push is a **production change**, and in most estates there is no staged copy of the proxy fleet to try it on first. The first place the change runs is the place users are. None of this makes a few thousand entries a problem. It makes *the feed's whole volume* a problem, and it makes the push itself something you plan rather than something you fire. ## Cost two: collateral, which is the real one Adversary infrastructure is rented, borrowed or stolen. Command-and-control lives on a VPS, on a compromised site on shared hosting, on a bucket or app inside a large SaaS platform, behind a CDN edge that fronts thousands of tenants. The address you were handed is very often carrying other people's traffic — including yours. Granularity is therefore the whole game, and it runs from safest to most dangerous: | Indicator | What a block hits | |---|---| | Full URL | one path on one host | | Hostname | one service | | Single address | every tenant on that address | | Prefix (a /24, a /16) | every tenant in the range, including yours | A feed that hands you netblocks is handing you outages, not prevention. ## The errors are not symmetrical Be explicit about the direction of each mistake. A wrong **match** costs an analyst a few minutes closing an alert. A wrong **block** costs users a failure that carries no message naming its cause: the help desk hears about it before the SOC does, the symptom looks like a vendor outage, and the loss is business revenue rather than security. That asymmetry, not the feed's confidence score, is what should drive how much of a feed you are willing to enforce. ## A selection policy you can defend 1. Enforce URLs and hostnames from high-confidence, recently observed sources — and prefer indicators your own incidents produced. 2. Enforce a bare address only when you have reason to believe the host is dedicated; refuse to enforce prefixes at all. 3. Keep an explicit, owned allow-list of CDN, shared-hosting and SaaS ranges you will never block at the address layer, with a reason recorded against each entry so nobody later tidies it away. 4. Everything you decline to enforce still goes somewhere: match it against your logs so a hit raises an alert. Declining to block is not declining to look. 5. Run any new list in alert-before-block first, and turn enforcement on one region at a time. ## What the volume claim actually says 'We block 1.8 million indicators' describes a subscription, not a defence. The defensible statements are narrower and much harder to produce: which indicators are enforced, what they hit last month, what business traffic they nearly hit, and which of them stopped something the rest of the stack would have missed. Volume is what a feed sells; specificity is what an enforcement path can afford.

  • Which is the cheaper thing to be wrong about — an indicator you blocked or one you only matched?
    The one you matched. A false match costs an analyst a few minutes and leaves the user unaffected. A false block produces a failure with no error message that names the SOC, so it is usually diagnosed by somebody else, late, as a vendor problem. That asymmetry is why most of a feed belongs in detection rather than enforcement.
  • Where do the indicators you decline to enforce actually go?
    Into matching against the records you already collect — proxy, DNS, flow and endpoint logs — so a hit raises an alert with context instead of dropping traffic. You keep full visibility of the feed and give up only the automatic block, which is the part that can take a business system down.
  • Does blocking a domain cost the same as blocking an address?
    The evaluation cost is broadly similar; the collateral cost is not. One hostname is one service, so a wrong hostname block breaks one thing. One address can be thousands of tenants behind a CDN or shared host, so a wrong address block breaks whatever else lives there — and you will not know what that is until somebody complains.

A block list is a bouncer with a photo album, not a filing cabinet. Every extra photo slows the door, and one blurry photo turns away a paying customer.

saying these in an interview costs you the question

  • Treats the number of blocked indicators as a security metric
  • Assumes every address on a feed is dedicated to the adversary
  • Calls a block list free because lookups are fast
  • Forgets that pushing a list is a production change
  • Blocks a prefix to catch one host on it

context

open as a page

An alert is enriched with a commercial threat-feed hit on a domain - what does that hit prove?

level: juniorimportance: must knowfreq 66%

basics

~20 s

It proves only that some curation process put that domain on a list at some point. It says nothing about what your host actually did. Treat a feed hit as one weighted input to a verdict, never as the verdict.

open as a page

Why run a newly published C2 domain back through five months of historic DNS logs?

level: juniorimportance: must knowfreq 72%

basics

~20 s

Because indicators arrive late. A block added today only matches traffic from today onward; the intrusion the indicator describes may already be months old in your stored logs. The retro sweep is the only way to see backwards.

open as a page

When researching a suspected C2 domain, what is the difference between passive and active collection?

level: juniorimportance: must knowfreq 64%

basics

~20 s

Passive collection reads records third parties already hold - passive DNS, certificate transparency, WHOIS history, stored scan data - so nothing reaches the adversary. Active collection resolves or connects to his host and writes a footprint into logs he controls.

open as a page

What must a priority intelligence requirement name that 'keep an eye on infostealer activity' does not?

level: juniorimportance: must knowfreq 68%

basics

~20 s

A priority intelligence requirement names a consumer, the decision they owe by a date, and what would count as an answer. 'Keep an eye on infostealer activity' names none of those, so nobody acts on it and it never closes.

open as a page

Why do intel teams track an intrusion as a numbered activity cluster instead of naming the actor?

level: juniorimportance: must knowfreq 66%

basics

~20 s

A cluster label records only that a set of intrusions share observed evidence such as infrastructure or tooling. An actor name asserts who is behind them, a claim defender telemetry rarely supports. Clusters split and merge; names resist that.

open as a page

What distinguishes strategic, operational and tactical threat intelligence products, and who is each one written for?

level: juniorimportance: must knowfreq 68%

basics

~20 s

They differ by reader and time horizon. Strategic products tell executives how the threat picture is shifting so they can fund decisions. Operational products tell an incident lead about a specific campaign. Tactical products give defenders the behaviours and artefacts to detect.

open as a page

What is the difference between STIX and TAXII when you ingest a partner's phishing-kit indicators?

level: juniorimportance: must knowfreq 70%

basics

~20 s

STIX is the data format: typed objects such as indicator, malware and relationship that describe adversary activity. TAXII is the HTTPS protocol that moves STIX objects between parties. One says what you mean, the other delivers it.

open as a page

Why can uploading a suspected implant to a public multi-scanner service burn your investigation?

level: middleimportance: must knowfreq 71%

basics

~20 s

An uploaded sample becomes visible to the platform's subscribers, and operators watch for their own tooling appearing there. The upload announces that the implant is discovered, and a targeted file often identifies the victim through embedded names, addresses or per-victim tokens.

open as a page

At 07:00 your CEO forwards a leak-site post naming a company like yours — how do you assess it?

level: seniorimportance: must knowfreq 55%

basics

~20 s

A leak-site listing proves someone published a claim, not that data was taken. Check the exact legal entity, then reseller and supplier lists, identity-provider sign-ins and SaaS audit trails. Answer with a likelihood, a confidence and a stated falsifier.

open as a page

One threat intelligence finding must reach the board, the IR lead and a detection engineer — one product or three?

level: seniorimportance: must knowfreq 46%

basics

~20 s

Three products from one judgement. Each reader takes a different decision at a different abstraction and on a different clock, so a single combined document forces every reader through the other two readers' material and gets skimmed by all of them.

open as a page

You forwarded a member's TLP:RED submission to a vendor. What does TLP:RED forbid, and what now?

level: seniorimportance: must knowfreq 55%

basics

~20 s

TLP:RED confines information to the specific exchange it was disclosed in, not your whole organisation. Stop distribution, get the vendor's written deletion, tell the submitting member yourself, and ask the originator to re-release if the vendor truly needs it.

open as a page

In an Admiralty Code rating like B2, what do the letter and the number each grade?

level: juniorimportance: should knowfreq 45%

basics

~20 s

The letter grades the source's track record (A completely reliable, down to F cannot be judged). The number grades that one report's credibility (1 confirmed by other sources, down to 6 cannot be judged). They are graded independently.

open as a page

Adversary C2 sits on the same CDN edge address as your payroll provider — how do you block it?

level: middleimportance: should knowfreq 44%

basics

~20 s

Block at a layer that can see the name. A forward proxy sees the requested hostname or TLS SNI and can deny one service on a shared address; a firewall matches the address alone and would take payroll down too.

open as a page

How do you measure a paid intel feed's unique contribution against the free sources you already run?

level: middleimportance: should knowfreq 47%

basics

~20 s

Normalise every source into one store, then measure a funnel: how many indicators only this feed carried, how many of those matched your own telemetry, and how many changed a verdict. Also measure how early it carried them.

open as a page

A retro sweep on a two-year-old C2 domain returns 400 hits on staff browsing a marketing site. What happened?

level: middleimportance: should knowfreq 55%

basics

~10 s

The matches are real but the intelligence expired: the domain changed hands and now serves a marketing agency. An indicator only means something inside the window during which the artefact was adversary-controlled.

open as a page

How do you turn a priority intelligence requirement into a collection plan when an MSSP runs part of your SOC?

level: middleimportance: should knowfreq 44%

basics

~20 s

Decompose the requirement into answerable sub-questions, then give each one a source, a named collector, a cadence and a definition of answered. With an MSSP, every line has to say who collects it - you or them - and lines nobody can collect are recorded as collection gaps.

open as a page

How do you detect circular reporting across three vendor write-ups of one campaign?

level: middleimportance: should knowfreq 42%

basics

~20 s

Trace every report back to a first-hand observation. Compare indicator lists, screenshots, dates and repeated errors; check publication order and citations. If all three descend from one original write-up, you hold one source, not three, and corroboration was never earned.

open as a page

Which shared observables justify merging two intrusions into one activity cluster?

level: middleimportance: should knowfreq 54%

basics

~20 s

Merge on overlaps the operators control and could not cheaply replace: a non-public implant with the same embedded configuration, a reused key or certificate, distinctive hands-on tradecraft. Shared hosting space, default TLS fingerprints and commodity tooling prove nothing alone.

open as a page

What does bottom line up front mean in a threat intelligence report, and what belongs in it?

level: middleimportance: should knowfreq 56%

basics

~20 s

Bottom line up front means the opening lines carry the judgement and the recommended action, not how the research was done. A reader who stops after the first paragraph still leaves with the conclusion and the decision they have to take.

open as a page

In a STIX 2.1 bundle, what does an indicator object claim that an observed-data object does not?

level: middleimportance: should knowfreq 52%

basics

~20 s

An indicator asserts a detection pattern its author believes signals malicious activity, so it is a forward-looking claim. Observed-data asserts only that particular artefacts were seen, when, and how many times, with no claim about malice.

open as a page

A /16 you pushed from a threat feed at 08:58 took the CRM offline at 09:05 — what do you do?

level: seniorimportance: should knowfreq 47%

basics

~20 s

Confirm from the deny logs that your push caused it, then make the smallest reversal that restores service. Put the removed range straight into matching so it is still watched, and re-enter the indicator narrowly.

open as a page

Tier-1 analysts never read your threat-intel enrichment panel - how do you fix the delivery?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Move the intel into surfaces analysts already work in: the alert's own fields, the endpoint tool's match list, the case record. Make each hit state its source, first-seen date and reason, then sample closed cases for verdicts that changed.

open as a page

A retro DNS sweep hits a C2 domain from a CI runner five months ago. What does that prove?

level: seniorimportance: should knowfreq 50%

basics

~10 s

A resolver record proves only that a client asked for that name at that time. It does not prove a connection followed, which process asked, that data moved, or that the host was compromised.

open as a page

An analyst browsed a live C2 panel from the office network and the cluster went dark within the hour - what have you lost?

level: seniorimportance: should knowfreq 44%

basics

~20 s

You have likely lost quiet observation of that infrastructure and told the operator which company is investigating him, because corporate address space is attributable. Rotation timed to the visit is strong evidence he noticed, not proof.

open as a page

A standing intelligence requirement has returned nothing in two years - how do you decide whether to retire it?

level: seniorimportance: should knowfreq 38%

basics

~20 s

Silence is ambiguous, so first establish whether anything was ever tasked and whether the source could have reported it. Retire only when the decision behind the requirement is gone or the targeting rationale never held - and record what would reopen it.

open as a page

Two intrusions at a bank share one exploited VPN appliance foothold - do you keep them in one activity cluster?

level: seniorimportance: should knowfreq 41%

basics

~10 s

No. Access to an internet-facing appliance is a commodity that gets sold and resold, so overlap confined to the front door links a supplier, not an operator. Split on the divergent post-access tradecraft.

open as a page

How do you run a new intel block list in alert-before-block mode, and what decides enforcement?

level: middleimportance: nice to knowfreq 34%

basics

~20 s

Load the list in alert-only mode, or match it against proxy and DNS logs off-box, for a fixed window. Then judge by which destinations matched and who would have been cut off — not by how many hits it produced.

open as a page

An assessment reads "likely, with low confidence" — is that a contradiction?

level: middleimportance: nice to knowfreq 36%

basics

~20 s

No. Likelihood is how probable the analyst thinks the claim is; confidence is how good the sourcing and reasoning behind that estimate are. Likely with low confidence means the estimate leans yes but little new information would move it.

open as a page

An intel report lands with 40 indicators and a 12-month sweep bills per terabyte scanned. How do you scope it?

level: seniorimportance: nice to knowfreq 38%

basics

~20 s

Cut on three axes before spending: indicator fidelity, a time window anchored to the campaign, and the cheapest source that can carry the artefact. Then test all forty in one pass, because the bill is bytes scanned, not searches run.

open as a page

showing 1–30 of 36