Skip to content
Notifications
Clear all

Guide: Creating custom watchlists for our specific tech stack

1 Posts
1 Users
0 Reactions
0 Views
(@brianl)
Estimable Member
Joined: 1 week ago
Posts: 113
Topic starter   [#5129]

Hello everyone. I’ve been reading through the existing reviews and discussions here for the past few weeks, and I want to thank you all for the detailed insights. They’ve been incredibly helpful as my organization evaluates Mandiant Threat Intel for integration into our security operations.

My background is primarily in ERP systems, specifically NetSuite, and managing the associated inventory and supply chain workflows for a manufacturing and B2B e-commerce operation. Because of this, our technology stack is quite specific. We have a mix of on-premise legacy manufacturing systems, cloud-based ERP and WMS platforms, and several custom-built integration layers that handle logistics data and reporting. We don't fit the standard enterprise mold, and I'm concerned about generic threat feeds missing the indicators most relevant to our unique digital assets and data flows.

I am currently in the planning stages of setting up Mandiant Threat Intel, and my primary goal is to create custom watchlists that are tailored to our environment. From what I’ve read, the platform is powerful, but the effectiveness seems to hinge on proper configuration. I want to ensure we focus our limited analyst attention on the threats that actually matter to our business, such as those targeting our specific versions of industrial control software, our e-commerce API endpoints, or the middleware that connects our NetSuite instance to our warehouse systems.

I have several questions about the practical aspects of building these custom watchlists. First, what is the best method for defining the criteria? Should we be focusing on specific malware families known to target supply chain software, or is it more effective to base lists on the specific IP ranges, domain patterns, and file hashes associated with our externally facing systems? Second, how does the integration handle the ingestion of our internal asset and application data? For example, can we feed a CSV export from our NetSuite environment, or data from our internal CMDB, to automatically seed or refine watchlist parameters?

Finally, I’m very interested in any lessons learned from members who have gone through a similar process for non-standard tech stacks. Are there pitfalls in creating watchlists that are too narrow, potentially missing novel threats? How do you balance the need for specificity with maintaining a broad enough net? Any guidance on structuring these initial lists, or examples of criteria that have proven valuable for manufacturing or logistics-focused environments, would be greatly appreciated.



   
Quote