Let's start with a data point from my own team: the last time we attempted to onboard a new analyst using ThreatConnect's official training modules, we logged over 14 hours of support time just to bridge the gap between what the videos showed and the actual UI we were paying for. That's not an efficiency problem; it's a fundamental failure in enablement.
My unpopular opinion is this: ThreatConnect's training library feels like it's preserved in amber from a 2018-era deployment. The assumption baked into every tutorial and guide is that the user has a foundational, almost innate, understanding of not just threat intelligence concepts, but of their own platform's now-deprecated workflows. They've added features—some of them quite powerful—but the learning materials haven't kept pace, leaving you to reverse-engineer how the new components interact with the old.
Here’s where it gets actively frustrating for anyone trying to build a process:
* The videos reference menu layouts and button placements that were redesigned two UI overhauls ago. You're constantly playing "find the control" while the perky voiceover explains steps that no longer exist.
* There's a glaring assumption that your org is using a specific, older method of indicator scoring and tag hierarchy. When we tried to implement their suggested playbook for a common phishing campaign pattern, the required "Legacy Connector" had been sunsetted six months prior, a fact mentioned nowhere in the training docs.
* The API examples are the worst offenders. The code snippets in the training portal for basic CRUD operations still use authentication methods that their own support team will tell you are deprecated. You only find out after your automation scripts fail and you've burned a week of dev time.
This creates a vicious cycle. New team members either become a massive drain on senior resources to get them up to speed, or they develop workarounds based on flawed or outdated instructions, which then gets baked into our own processes. For a platform whose entire value proposition is precision and current intelligence, the disconnect between the product's capabilities and its educational content is almost sardonic.
I'm not arguing the platform isn't powerful. I'm arguing that its ROI is directly undermined by an onboarding and continuous education experience that feels like an afterthought. We've had to develop and maintain our own internal wiki just to document the delta between what the training says and what the platform actually does. That shouldn't be a necessary value-add for a customer.
Has anyone else built a parallel "shadow curriculum" for their teams, or found a reliable way to pressure their CSM for updated, version-specific materials? I'm curious what the real-world workarounds are.
-- maven
MQLs are a vanity metric.