The (REAL) Result
A (somewhat) automated system
providing centralized threat data
& intelligence management made
up of a single source of truth
supported by purpose built
collection, processing, and
analysis integrations.
Slide 51
Slide 51 text
Lessons
Slide 52
Slide 52 text
This isn't easy
But parts are.
Slide 53
Slide 53 text
Threat Intel Tools Work
When They're Integrated
~
collection | analysis | dissemination
Slide 54
Slide 54 text
High Value Investments
Tool: Paterva Maltego ~ $760
Service: PassiveTotal ~ $??
Learning: Introducing Python ~
$33
Slide 55
Slide 55 text
Learn to Code
Slide 56
Slide 56 text
Unix Philosophy
Small is beautiful
Make each program do one thing
well
Portability over efficiency
Store data in flat files
Make every program a filter
Slide 57
Slide 57 text
Data formats matter less than format openness
CSV & JSON
Slide 58
Slide 58 text
Perfect
Is the Enemy Of
Good
Slide 59
Slide 59 text
The Future:
Scaling Up Collection & Storage
Expanded Threat_Notes APIs &
Integrations
Reputation & Fuzzy Indicators