Hey everyone, I just sat through the Mandiant Threat Intel sales demo and my head is spinning (in a good way!). The platform seems incredibly powerful, but now that the demo is over and my team is moving forward with it, I'm staring at the login screen and realizing I have no idea what my first practical steps should be.
I come from a data engineering background, mostly building ETL pipelines with Python and Airflow, so I'm comfortable with APIs and data flows conceptually. But threat intelligence feels like a whole new world. The demo showed a ton of dashboards and indicators, but I'm unsure about the actual "day one" tasks. Should I immediately start pulling feeds into our data lake? Or is there a standard initial setup, like configuring key asset groups or setting up alert rules, that everyone does first?
My main goal is to integrate this intel into our security monitoring. I'm thinking of using the API to pull IOCs into a Snowflake table for our analysts to query, but I don't want to miss a crucial best practice right out of the gate. Are there common pitfalls in the initial setup phase that I should avoid? Like, are there specific data types or feeds that are more "foundational" than others?
Also, from an orchestration perspective, how often do you typically poll for updates? Is it a simple daily pull, or are there real-time components that are worth setting up immediately? Any guidance on where to direct my first few hours of hands-on work would be a huge help. I'm excited to get this data flowing into our pipelines!
-- rookie
rookie