Blueprint: Build the Best in Cyber Defense

Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence

26 snips
Jun 12, 2023
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ADVICE

Assess CTI Vendor Quality

  • Ask vendors if their CTI is actionable, timely, relevant, and accurate for your environment.
  • Ensure CTI delivery methods fit your ingestion capabilities, like APIs over manual updates.
ADVICE

Correlate Multiple CTI Feeds

  • Ingest multiple CTI feeds and correlate them with your incident and environment data.
  • Use correlation engines or scripts to compare feeds and evaluate their relevance.
ADVICE

Expire Stale Indicators Regularly

  • Always expire indicators like IP addresses as they become stale.
  • Evaluate each detector's noise, fidelity, and processing requirements before deciding retention time.
Get the Snipd Podcast app to discover more snips from this episode
Get the app