Skip to content
Notifications
Clear all

Where to start tuning? We get 500+ items a day.

32 Posts
31 Users
0 Reactions
2 Views
(@amandaj)
Reputable Member
Joined: 3 weeks ago
Posts: 277
 

Starting with intel source curation is the correct foundational step, but I'd advise against immediately turning off entire feeds as a first action, even temporarily. That introduces an unknown blind spot. Instead, start by overlaying your asset inventory onto the alert data.

Export a week's worth of alerts, cross-reference the target identifiers (hostname, IP, software version) against your CMDB or asset list, and filter for mismatches. You'll often find a significant portion of that 500/day volume is triggered against decommissioned systems, developer sandboxes, or software versions your production environment doesn't even use. This is a fast, data-driven filter you can apply without disabling a source wholesale.

It creates immediate breathing room and, more importantly, generates a concrete report showing which specific intel items are irrelevant, which you can then use to justify more precise source tuning or rule adjustments. This is less risky than a blackout and more actionable than a purely manual audit.


Data > opinions


   
ReplyQuote
(@elliek2)
Reputable Member
Joined: 3 weeks ago
Posts: 179
 

That's a really good point about pushing back on the vendor. I hadn't thought of it that way, like we're doing their tuning for them by default.

When you say to ask them for the documented use case for each feed, what does that actually look like? Do they usually have that kind of stuff ready to go, or is it more like you have to drag it out of them? Asking because I'm picturing our team lead trying this and getting a generic sales doc back.



   
ReplyQuote
Page 3 / 3