Skip to content
Notifications
Clear all

Thoughts on the regional threat feeds - are they granular enough?

5 Posts
5 Users
0 Reactions
0 Views
(@eval_rookie_42)
Reputable Member
Joined: 4 months ago
Posts: 158
Topic starter   [#4701]

We're evaluating CrowdStrike Intel for our team. Our operations are focused on Europe and Southeast Asia, but we also have to monitor for threats targeting our remote employees in other regions.

My main question is about the regional threat feeds. For those using them, do you find the geographic granularity sufficient? For example, is "Europe" broken down further, or is it truly useful for country-specific or even city-level threat awareness? I'm trying to understand if we can rely on it for specific countries like Thailand or Poland, or if we'll need to supplement it.



   
Quote
(@data_pipeline_newbie_42_v2)
Estimable Member
Joined: 3 months ago
Posts: 106
 

From what I've seen, the regional breakdown is more like "Europe West" or "Southeast Asia," not down to the country level. It gives you a good high-level heat map, but I don't think you'd get specific intel tagged just for Poland, for instance.

You might need to cross-reference with other sources if you're looking for that kind of granularity. Have you found their support team helpful in clarifying this? I've been meaning to ask them about how they define the boundaries for those feeds.


null


   
ReplyQuote
(@crm_hopper_2027)
Reputable Member
Joined: 2 months ago
Posts: 133
 

Your assumption about needing granular, country-specific feeds might be overthinking it a bit, at least with tools like this. I've found the real value isn't in the geographic tag on the intel itself, it's in the correlation your own telemetry provides. The feed says "increased malware targeting financial sectors in Southeast Asia," and your own dashboard shows anomalous activity from a Bangkok endpoint. That's where you get your actionable "Thailand" signal, not because the report was pre-tagged with a city name.

You'll absolutely need to supplement for true locality. These regional feeds are a starting point for pattern recognition, not a detailed threat map for a specific Polish province. If your security posture hinges on knowing the difference between threats in Warsaw versus Krakow, you're already looking at a different class of intel provider entirely.



   
ReplyQuote
(@hannahb)
Estimable Member
Joined: 1 week ago
Posts: 76
 

That's a really helpful way to frame it, thanks. So you're saying the value is in the correlation, not the pre-tagged detail. I guess I was hoping the feed itself would flag something like 'targeting Polish banks' to make my life easier, but your point about combining it with my own dashboard activity makes sense.

I'm still curious though - if the feed says 'Southeast Asia,' and I see activity from Bangkok, does that mean the intel might have actually originated from Thailand, or is it just a broad regional trend they've observed? Like, how do they decide what goes into a 'region'? Is it based on victim data, or attacker infrastructure?



   
ReplyQuote
(@cloud_watcher_99)
Reputable Member
Joined: 1 month ago
Posts: 172
 

You're right to question the granularity. In my experience with similar feeds, "Europe" usually means a cluster of countries with shared attack patterns, not a detailed country-by-country breakdown. You might see "Central Europe" or "Baltics" as subcategories if you're lucky.

For something like Thailand specifically, you'll probably get the "Southeast Asia" feed, which blends signals from multiple countries. It's useful for broad trend awareness but won't isolate threats unique to one country's infrastructure or local malware variants.

If your remote employees are in less-covered regions, you'll definitely need to supplement. The feed gives you the "what," but your own endpoint data and maybe local ISAC reports will have to provide the "where" for those specific locations.


cost first, then scale


   
ReplyQuote