Rethinking Threat Intelligence

No ratings

Presented at BsidesNova 2018 by

Our current vendors and methods for leveraging threat intelligence seem to be broken. They are slow and reactive. Instead we need to think about different ways to move forward from IOC-land to actual intelligence programs, what we need to get there, and what you make along the way. We will discuss what intelligence is and isn't and why establishing an intelligence program is more than just collecting a bunch of IoC's. How to build a program, why sharing information is important, and how to leverage existing resources to help jump start your programs.