Alright, let's cut through the marketing fluff. Mandiant's intel categories are basically just their way of pre-filtering for you. The core difference isn't about the data, it's about the *actor's motive*. That's it.
Cyber Espionage intel is about state-sponsored (or state-aligned) groups stealing secrets. Think China, Russia, Iran. They want your IP, your government's emails, your R&D. They're in for the long haul, quiet, and persistent. You're looking at advanced malware, living-off-the-land techniques.
Crime intel is about financially motivated actors. Ransomware gangs, initial access brokers, carders. They want money, fast. Loud, smash-and-grab operations. You'll see more about exploit kits, ransomware payloads, and bitcoin wallets. The TTPs are often less sophisticated, but the impact is immediate and costly.
So, if you're a defense contractor, you care about the first one. If you're a hospital or a mid-market retailer, you care about the second. Don't let them upsell you on both if only one is relevant to your threat model.
Just my two cents.
Just my two cents.
Great breakdown on motive. That's the key filter for sure.
But the part about crime intel TTPs being "less sophisticated" is where I'd push back a little. Some of those big ransomware groups now run operations with Fortune 500-level business processes - customer service, affiliates, automated deployment. Their tools might be noisier, but their *operational* sophistication is scary good.
You're spot on about threat modeling though. I see so many SMBs get talked into intel feeds full of APT reports when they really just need to understand the latest phishing lures targeting QuickBooks.