Putting the Intelligence Back in Threat Intel (Because Math)

No ratings

Presented at TechnoSecurity&DigitalForensics 2019 by

Threat Intelligence isn't about having a sea of honeypots, raw source feeds of bad IP addresses, domains & hashes, or log files -- we already have that; it's about taking that data, turning it into information so we can make decisions and take action!Let's be honest, raw data is everywhere; truth is, we're drowning in it. We have the ability to collect data from almost everywhere on a near constant basis; however, the mere collection and retention of data does not mean we have "Threat Intelligence", it just means we're hoarding data.Analysis is required; only through analysis can we produce actionable intelligence and bring that business value to the table. This session will cover various methods available, when they are appropriate, and how they can be leveraged to help secure your organization and reduce risk. After completing this session, attendees will be able to: Understand the need for defined information requirements relating to threat intelligence; Improve their knowledge regarding how leveraging threat intelligence lowers risk to theriorganization; Better understand how a defined and consistent application of analysis techniques address the various risks (strategic, operational & tactical); and Better understand the business value that a properly implemented threat intelligence program brings to the organization.