CyPorg Profile picture
IR / Threat Intel
Oct 27, 2018 11 tweets 3 min read
@MalwareHobbit This is how I see CTI. First and foremost CTI should not be separated from DF / IR or security monitoring (SOC Analysts). Instead CTI should be integrated into both with CTI feeding DF / IR / SOC and vice versa. I think CTI at its core is misunderstood. Many big name organizations treat CTI as Infosec Journalists. Intel consists of pulling data from other data sources and vetting it. Some consider this to be a core functionality of CTI... yet I disagree strongly.