We’re bringing on two new analysts and they’ll be using Mandiant Threat Intel from day one. I’m helping with onboarding, but I don’t have a formal security background myself.
What’s the most effective training path you’ve seen? I’m thinking about hands-on labs, but also how to teach the right mindset for using the intel in reports and alerts. Are there specific use cases or common workflows we should drill first? Any pitfalls to avoid during training?
I'm a junior engineer at a mid-sized SaaS company. We use Mandiant Threat Intel feeds integrated into our SOC's SIEM and a few internal dashboards.
**Time to first value:** For new analysts, expect a 2-3 week ramp before they can independently judge report relevance. The key was drilling IOC pivots and source confidence ratings from day one.
**Critical starting workflow:** We had them shadow a senior analyst triaging our automated daily digest. The first hands-on task was writing a summary for one threat actor, using only the Mandiant portal, to force source familiarity.
**Common new hire pitfall:** They'd often treat all intel as equally urgent. We built a simple checklist for them to score indicators based on our industry and asset exposure, which cut down on false-positive alerts.
**Training resource gap:** The official docs are thorough but dense. We got the best results by creating internal "cheat sheets" for our specific use cases, like correlating with our vuln scanner or enriching our ticketing system.
For your use case, I'd start with shadowing on the daily digest and then move to those summary reports. To pick a specific training method, tell us how your team currently prioritizes alerts and if the new hires have any prior intel analysis experience.
learning every day
That timeline and workflow you described is spot on. The shadowing on the daily digest is crucial. We found that pairing it with a structured debrief question set for the senior analyst to use, like "Why did you dismiss this item?" or "What made you escalate that one?", accelerated the mindset shift.
Your point about the checklist for scoring indicators is excellent. We formalized a similar step into a lightweight internal scoring matrix. It assigned points for things like our geographic footprint alignment with the threat actor's TTPs, which directly tied intel urgency back to our specific business risk. This moved them from generic triage to contextual analysis much faster.
Could you share the structure of your IOC pivot drills? We started with simple domain-to-IP lookups but found adding a second step, like having them assess the associated malware family's prevalence in our industry, made the exercise more valuable.
Less spend, more headroom.