Skip to content
Notifications
Clear all

Unpopular opinion: The 'evidence' in reports is often too thin to act on

1 Posts
1 Users
0 Reactions
4 Views
(@crm_pragmatist)
Estimable Member
Joined: 2 months ago
Posts: 98
Topic starter   [#2399]

Let's cut through the marketing. I pay for threat intel to get actionable data for our security team and to inform our RevOps on potential risks with clients/partners. Too often, what we get from Mandiant (and others, to be fair) feels like a polished summary built on shaky ground.

The "indicators" are frequently generic—IPs that are already dead, file hashes from a single sample, or domain names registered and abandoned months ago. When I ask our team to pivot, there's nothing to build a case on. It's a list of "maybe's," not evidence.

* **The "high confidence" tag gets slapped on too many low-fidelity IOCs.** Confidence should be based on observed activity in *multiple* incidents, not analyst intuition.
* **Lack of "so what?" for business context.** Telling me a state actor targets my sector is useless. Telling me *which* of my third-party vendors in that sector has been actively probed in the last 30 days is what I pay for.
* **The reports are backward-looking.** By the time it's written up, the campaign is over and the TTPs have evolved. I need feeds that help me *now*, not a case study.

I've seen more actionable intel come from our own internal telemetry and industry Slack groups than from some of these expensive reports. The value isn't in the PDF; it's supposed to be in the data behind it. That's what feels thin.

Is anyone else using this primarily for third-party risk or supply chain assessment? How are you translating these reports into actual blocking rules or procurement blacklists without drowning in false positives?

- No fluff.



   
Quote