Threat Intelligence & OSINT
How a defender produces and consumes intelligence: requirements tied to a decision, collection that does not tip an operator off, clustering without over-claiming, and intel that reaches a control.
on this pageshowhide
explore
- Producing Intel12 questions
- Intelligence Requirements4 questions
- Open-Source Tradecraft4 questions
- Source Grading & Confidence4 questions
- Structuring & Exchange12 questions
- Activity Clustering4 questions
- Sharing Formats & Platforms4 questions
- Writing the Product4 questions
- From Feed to Decision12 questions
- Blocking at Scale4 questions
- Retro Search & Expiry4 questions
- Earning the Subscription4 questions
questions
page 2 of 2Your threat-feed renewal costs the same as twenty EDR seats - how do you make the call?
basics
~20 sBring the measured funnel - unique, matched, acted on - and the verdicts that came out differently, then weigh them against what the same money buys in telemetry you own. Halving to the collection that worked is often the right answer.
Before an analyst registers a research persona on a criminal forum, what do you agree with counsel?
basics
~20 sA written, counsel-approved collection policy: never authenticate to systems you do not own, never buy stolen data, never fund a sanctioned party, and use an invented identity on infrastructure and funding that do not trace back to the company.
Your intelligence consumer says 'just send me anything relevant' - how do you get real requirements out of that?
basics
~20 sWork backwards from the decisions on that person's calendar, draft a small ranked set of requirements naming each decision and its date, and make them cut it down. Priority comes from their competing decisions, not from analyst interest.
You published an activity-cluster merge six weeks ago and new evidence splits it - what do you owe the people who acted on it?
basics
~20 sCorrect it with at least the reach of the original claim, and be precise: the shared indicators still stand, the linkage does not. Then fix what let a merge built on commodity overlap be published.
Your quarterly threat intelligence products are read and praised but change nothing — how do you fix that?
basics
~20 sStop counting products and start tracking decisions. Every product should name one action with an owner and a date, and you should go back and record whether it was taken, refused or deferred. A recorded refusal is a real outcome; silence is the failure.
Half your health-sector ISAC cannot consume a TAXII feed at all. How do you make sharing produce value?
basics
~20 sPublish on two tracks: machine-readable STIX for members with platforms, and a short note naming a few blockable values and one action for members without. Measure actions taken, not objects published, and keep default markings loose enough that members still submit.
showing 31–36 of 36