I really, really dislike threat intelligence feeds. It seems like a more complicated and enterprise spanning blacklist. And, we all know the historical failures of blacklisting in AV. However, threat intelligence, coupled with the right visibility and implementation is incredibly valuable. In this presentation we will cover how to use the work from JPCert and MITRE ATT&CK to better implement defensive solutions. And, we will cover how to do it all for free.