Hi everyone, I hope this is the right place to ask this. I’m fairly new to this community and to this whole side of business operations, so please bear with me if my question seems a bit basic. I’m more familiar with the bookkeeping and invoicing side of things, but our small business has grown to the point where we need to think more seriously about cybersecurity.
We’ve been hearing a lot about ThreatConnect from a few other business owners, and I’m trying to understand if it would be a good fit for us. My main concern, which I’ve seen mentioned in passing but not deeply explained, is about detecting those really slow, stealthy attacks. The kind that might slip under the radar because they don’t look like a sudden burst of activity.
From my world, it’s a bit like trying to spot a tiny, recurring fraudulent expense that’s designed to look normal—it’s easy to miss in the daily flow. I’ve read that ThreatConnect is good at correlation and threat intelligence, but can it reliably pick up on that “low-and-slow” command-and-control traffic? The sort of thing where a compromised device might just send out a tiny, seemingly innocent packet every few hours or days?
I’m worried that as a smaller team without a dedicated security person, we might get a tool that’s powerful but could miss these subtle, drawn-out threats because we don’t know how to tune it properly. Are there specific features or modules within ThreatConnect that are particularly good for this? Or does it require a lot of custom rule-building that might be over our heads?
Any insights from your own experiences, especially if you’re in a smaller shop, would be so appreciated. Thank you for your patience