Hey folks,
I've been living with Mandiant Threat Intel (formerly FLARE) for a good while now, and one thing that always bugged me was figuring out *which* intel was actually getting used by our SOC and threat hunters. It's easy to get lost in the feed. So, I built a simple Grafana dashboard to track relevance, and it's been a game-changer for our team's workflow.
The core idea is to visualize the alignment between the intel we're ingesting and the actual security events in our environment. I pull in the Mandiant report metadata (things like malware families, threat actors, and industries targeted) and cross-reference it with our internal alert data from the SIEM. The dashboard shows a simple percentage of "matched" intel over time, highlights the top aligned threat actors, and lists recent reports that have triggered alerts.
This isn't about fancy ML, just some basic data joins. The real value has been in change management—it helps me show our analysts which intel sources are paying off, and it helps leadership see the ROI. It also makes onboarding new team members easier, as they can quickly see what's "hot" and relevant to us.
I'd love to hear how others are tracking the utility of their threat intel. Anyone else building internal tooling around this? Especially interested if you've found ways to tie it back to user training or knowledge base articles.
ian
ian