Skip to content
Notifications
Clear all

Anyone else's alerting slow to trigger on newly published CVEs?

1 Posts
1 Users
0 Reactions
4 Views
(@ethanc)
Eminent Member
Joined: 4 days ago
Posts: 25
Topic starter   [#20881]

Hey everyone, hope you're having a productive week.

I wanted to bring up something I've been observing in our workflow over the last few months and see if it's a shared experience. We rely heavily on Mandiant's feed for CVE alerts to kick off our internal triage and patching protocols. Lately, I've noticed a concerning pattern: there seems to be a significant lag—sometimes stretching to several hours—between when a critical CVE is published (say, on NVD or even other intel sources) and when our corresponding alert from Mandiant actually triggers.

Just last Tuesday, CVE-2024-***** (high-profile cloud infra one) was making rounds on vendor blogs and social media by 10 AM. Our internal monitoring picked up chatter, but our formal Mandiant alert didn't land in our SIEM or email digest until after 3 PM. That's a 5+ hour window where we were aware, but our automated systems dependent on *their* feed weren't officially "notified." We had to manually override and push an interim rule.

This creates a real operational gap. The whole point of paying for a premium threat intel feed is to get *actionable*, *timely* data, especially for the big, exploitable vulnerabilities.

I'm trying to figure out if this is:
* **Something on our end:** Maybe our integration or polling interval needs tuning? But we're on their recommended push API setup.
* **A universal throttling/delay:** Is Mandiant intentionally holding back to add analysis/context, causing a slower time-to-first-alert?
* **A recent performance issue:** Has anyone else seen this lag increase specifically in Q2 of this year?

What's your experience been?
* Are your alerting times consistently under, say, 60 minutes from initial public disclosure?
* Have you compared this lag to other threat intel providers you might use alongside Mandiant?
* Any workarounds you've implemented (like supplementing with a faster, less contextual feed for initial alerting)?

I love the depth of Mandiant's context and their written reports, but speed is critical in this first phase. I'm starting to think we might need a two-tier system: a "blink" alert from a faster source, then enriched data from Mandiant later. Kinda defeats the purpose of a single consolidated feed, though.

Would really appreciate your thoughts and any data points you can share.

—ec


Test, measure, repeat


   
Quote