Hey folks,
I just got the update notification for the new Custom Watchlists feature in CrowdStrike Intel. On the surface, it looks like a handy way to bookmark specific searches—like for a particular threat actor, malware family, or TTP you're tracking.
But I'm trying to figure out if it's *more* than just a saved search with a fancy name. Does it:
- Allow for automated alerts when new intel matches the watchlist criteria?
- Enable sharing or collaboration with other team members in the portal?
- Pull in data from outside the standard Intel search, like from internal reporting?
In our B2B space, we're often tracking very specific vendor-related threats or industry verticals. If this is just a UI convenience, it's nice but maybe not a game-changer. If it's a dynamic collection that can feed into other workflows or dashboards, that could be really powerful for building a more proactive threat intel program.
Has anyone had a chance to dig into the docs or test it yet? I'm particularly curious about the integration points. Keen to hear your initial impressions.
~ Amy