ThreatQuotient Launches in Bid to Improve Threat Intelligence

Published: Jun 4, 2015
Updated: Feb 2, 2021
2 minute read
threat intelligence
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

At the Black Hat USA 2014 conference, Ryan Trost spoke about the challenges and opportunities of building a threat intelligence library from multiple sources. Trost is the co-founder and CIO of ThreatQuotient, which officially launched on June 3, turning part of the strategy that was discussed at Black Hat into a real product, ThreatQ.

The goal of ThreatQuotient, according to Trost, is enable an organization to manipulate and understand threat intelligence data from any number of different sources. The idea of being able to handle and understand multiple forms of threat data is not a new one and is being chased by a number of vendors, including ThreatStream.

“What differentiates us from others in the market is the fact that we’re completely on-premises,” Trost told eWEEK. “We’re a middleware platform for threat intelligence.”

From a core technology perspective, Trost explained that ThreatQ includes a number of Python language-based connectors that reach out to different threat intelligence source APIs to pull data in. In addition, the data can be enriched by ThreatQ for additional context.

Trost said a traditional Security Information and Event Management (SIEM) platform is limited in that it is only correlating alerts. “If a malicious attack isn’t enough to trigger an alert, the threat intelligence in the SIEM isn’t doing anything,” he said.

The ThreatQ model is about pushing threat intelligence to an organization’s existing tools, including firewalls, to make faster use of the data to secure an enterprise. Trost added that the biggest challenge for his company is that not all organizations have mature threat intelligence processes.

“The challenge for us is how we build a tool that can cater to both advanced as well as less advanced organizations that everyone can benefit from,” he said. “We don’t want to force a round block into a square hole.”

Trost said his company’s ThreatQ platform can also be used to help do a bake-off across multiple commercial threat intelligence vendors that an organization might be considering. With ThreatQ, it’s possible for an organization to look at the frequency of reports and the types of threat indicators that are being distributed from a given commercial threat intelligence vendor.

“Customers can do a bake-off and determine which threat intelligence provider is the best one for them,” Trost said. “For example, they can evaluate the C2 [command and control] elements that are attacking the enterprise against the threat indicators provided by the threat intelligence vendors.”

Advertisement

The next step for ThreatQuotient will be a second version of ThreatQ that will further improve the user interface and experience for enterprise analysts.

Sean Michael Kerner is a senior editor at eWEEK and InternetNews.com. Follow him on Twitter @TechJournalist.

Sean Michael Kerner

Sean Michael Kerner is an Internet consultant, strategist, and writer for several leading IT business web sites.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。