Blueprint: Build the Best in Cyber Defense cover image

Strategy 6: Illuminate Adversaries with Cyber Threat Intelligence

Blueprint: Build the Best in Cyber Defense

00:00

Should We Expire Indicators Out of Our Threat Intelligence Platform?

A core piece of having a threat intelligence platform is like, if you see the same thing twice, that's the tool that should be able to point it out. That being said, we have had like some detectors that have been sitting around for three years and have never fired. So I think even for IOCs or something else, it's not an easy like, oh, you rotate off after 18 months or three minutes or whatever it is. You have to think about it from your whole collection strategy and your alerting strategy and figure out where it fits.

Transcript
Play full episode

The AI-powered Podcast Player

Save insights by tapping your headphones, chat with episodes, discover the best highlights - and more!
App store bannerPlay store banner
Get the app