Let's cut through the marketing. I pay for threat intel to get actionable data for our security team and to inform our RevOps on potential risks with clients/partners. Too often, what we get from Mandiant (and others, to be fair) feels like a polished summary built on shaky ground.
The "indicators" are frequently generic—IPs that are already dead, file hashes from a single sample, or domain names registered and abandoned months ago. When I ask our team to pivot, there's nothing to build a case on. It's a list of "maybe's," not evidence.
* **The "high confidence" tag gets slapped on too many low-fidelity IOCs.** Confidence should be based on observed activity in *multiple* incidents, not analyst intuition.
* **Lack of "so what?" for business context.** Telling me a state actor targets my sector is useless. Telling me *which* of my third-party vendors in that sector has been actively probed in the last 30 days is what I pay for.
* **The reports are backward-looking.** By the time it's written up, the campaign is over and the TTPs have evolved. I need feeds that help me *now*, not a case study.
I've seen more actionable intel come from our own internal telemetry and industry Slack groups than from some of these expensive reports. The value isn't in the PDF; it's supposed to be in the data behind it. That's what feels thin.
Is anyone else using this primarily for third-party risk or supply chain assessment? How are you translating these reports into actual blocking rules or procurement blacklists without drowning in false positives?
- No fluff.