Talk With an Expert

Threat Intel Processing at Scale

Threat Intel Processing at Scale (PDF, 2.10MB)Published: 27 Mar, 2019
Created by:
Don Franke

This paper examines the common but flawed practice of implicitly assigning trust to threat indicators (or intel) that are shared by external providers. These indicators are often deployed automatically to security controls without adequate vetting, resulting in false positives and a false sense of security. This paper proposes a solution for how to implement an intel analysis process that separates noise from useful indicators, can handle a large volume of information received regularly and is scalable despite limited analyst resources.

Threat Intel Processing at Scale