Why The Hate for Threat Intelligence Feeds?
ID: 195a2ef6-9877-5965-bcba-d931de73a0da
STIX ID: report--195a2ef6-9877-5965-bcba-d931de73a0da
Feed Name: Black Hills Infosec Blog
This editorial critiques the practical value of commercial threat intelligence feeds, asserting they function like ineffective blacklists with minimal overlap and limited applicability to targeted attacks, as reflected by cited Verizon DBIR statistics (3% feed overlap; 70–90% unique malware per organization). The author recommends investing in internal threat intelligence and peer sharing, and focusing detection on enduring adversary behaviors—persistence, command-and-control, and lateral movement—highlighting common techniques (e.g., SMB pivoting, token impersonation, pass-the-hash, password spraying) and tools like Microsoft Advanced Threat Analytics as more reliable defenses.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
