Hi everyone! I’ve been lurking here for a bit and finally decided to post. I’m currently evaluating Mandiant Threat Intel (among a few others) as part of a security tooling refresh at my company.
I keep hearing about the sheer volume of IOCs that services like this can generate daily. Frankly, the idea of getting thousands of new indicators every day is a bit overwhelming. 😅 My team is relatively small, and we’re not full-time threat analysts.
So, for those of you using Mandiant's feeds in production: **What is your actual, practical method for handling that daily firehose?**
Do you:
- Filter heavily by confidence score or malware family from the start?
- Feed everything into a SIEM and just alert on a subset?
- Use it more for retrospective hunting, pulling in IOCs only when investigating something specific?
I’m especially curious about the balance between automation and human review. How much time does managing this intake actually take once it’s set up? Any “gotchas” or things you wish you’d known before turning the tap on?
New here!
Just my two cents.