Hey everyone, I've been reading through the threads here on Mandiant. Thanks for all the insights so far.
I'm looking at their threat intel specifically for the financial sector. In marketing automation, we obsess over data quality—bad data ruins everything. So for something like this, the false positive rate is huge.
Does anyone have concrete numbers or even ballpark figures on their false positive rate for financial sector IOCs or alerts? I'm thinking about things like fraudulent domain detection or malware hashes tied to banking trojans. If we're going to integrate this data into our security monitoring (which ties into our CRM and client data), I need to know how much noise we're signing up for.
Are we talking 5%, 10%, higher? And does it vary a lot between, say, phishing intel vs. ransomware alerts? Any real-world workflow experiences would be super helpful.