Intel 471’s Brandon Hoffman on Operationalizing Threat Intelligence

Transcription

hi I'm James McGuire here at the RSA conference with Brandon Hoffman Chief strategy officer for Intel 471 Brandon thanks for talking with us James thanks for having me I'm excited to be here today all right so let's talk about operationalizing threat intelligence but first tell me a bit if you would about Intel 471 how does the company serve its clients yeah so Intel 471 is a premier provider of threat intelligence we're specifically focused on close sourced or some people call dark web threat intelligence which means it's uh not so easy to get so we focus on that we have researchers all around the world who collect information and we process that information to a usable format we share that with our customers through our platforms what about operationalizing threat intelligence what is difficult about that for companies what's Difficult about it is uh traditionally threat intelligence came in a couple different flavors there's malware related threat intelligence like indicators those are somewhat easier for customers to operationalize because it's a technical component that you can put in another technical system but real adversary Focus threat intelligence which is one of the things that we specialize in is difficult because it generally came in a report format so what customers would need is they would need a group of analysts or threat intelligence experts on their side on their bench so to speak working inside the company who knew how to kind of dissect that information process it and use it and apply it to the problems inside the company itself as opposed to uh you you know something like a technical indicator which you could put into a Sim or a sore or a firewall and it would just kind of do what it needs to do so that's becomes the challenge there's a lot of Rich data available inside of threat intelligence and unlocking the power of it into an operational system is kind of where we're focused because that's one of the biggest challenges we see today in the market so there's a number of different types of operationalizing threat intelligence products I'm sure that some companies are confused how do I select one what advice would you give them well the first challenge of course is selecting what type of intelligence is right for you the way we view this is that there's a variety of of different kind of levels that you work your way through it also depends on the problems the customers are facing so we have things like open source intelligence we have vulnerability intelligence there's malware intelligence there adversary intelligence so depending on the problem that the company is trying to solve and how Integrated Security operations and threat intelligence itself is into the business fabric will help you kind of decide what you need now on the operational system side you have things like tips you have Sims you have sores you have EDR there's a variety of different operational systems these are the systems that customers run in their Network or uh on their systems that help them enforce security controls and getting that threat intelligence to those uh will also dictate which solution you may choose so the type of intelligence you have the problem you're trying to solve will tell you kind of what systems you want to apply the problem to is it usually done by size of company or not necessarily you would think so right yeah you would think so but actually no sometimes it's the industry that they're in they're usually trying to solve a discrete set of problems in certain industries that will determine you know for example oil and gas has a very specific problem set um that sometimes all of threat and Teng is not applicable to that's just an example um sometimes it's about scale but really it's about the team that's working inside the company and the company's security Focus some companies are focused on securing endpoints some are focused on securing consumer experience through a website so really depending on what they're trying to secure that will also dictate what they need all right let's drill down into the 471 product offering what what what Solutions should people know about Intel 471 yeah so our classic offering is a product we call Titan uh that's a threat intelligence uh portal where customers can go and they can kind of set their requirements what they're looking for the things that are important to them uh like Hey we're looking for this type of threat actor or we're concerned about this type of attack what information do you have inside of that portal there's a variety of different ways that the information is delivered some of it's just raw information that somebody could consume and use on their side some of it's finished reporting that would might go to the executive level um some of it's very technical that people will consume through a programmatic interface an API and then about 18 months or two years ago we acquired a solution called spiderfoot which is an attack surface solution so that's really focused on helping customers understand what's available external to our environment that somebody could attack what systems do we have exposed what vulnerabilities things like like that and then actually last week we finished another acquisition of cyborg security which is a premier provider of threat hunting so they have a whole platform called Hunter that helps really actually operationalize our data into those Downstream systems by taking adversary techniques tactics and procedures behavioral information and also classic indicators and put them into hunt packages that you can then push into those systems to find out do I have a problem okay it makes it easier in sense for the security folks exactly yeah much easier for them all right so let's look to the future I think companies want to know you know what's coming say you know 2 to 4 years from now and how can we get ready for it now so if you look into your crystal ball what do you see in the future well I mean short term we're seeing consolidation across the market where people who uh customers um and suppliers are collecting more different types of data to provide it in One Singular place that's one thing that we kind of knew was going to happen but again this operationalization of the data I think threat intelligence is going through this transformational period where uh it was very popular for a long time to get these reports and to be able to somewhat digest this information in systems but I think the focus on providing return on investment right outside of threat and just like any other business is really predicated on customers being able to use that in operational systems and see results and actually meaningfully reduce risk and you know we believe you know that a big bet for us on that is through threat hunting uh and the Really for me the combination of attack surface really focused threat intelligence operationalized through threat hunting really will make a big impact for customers and that's where we think the future is going well you know you use the phrase meaningfully reduce the risk that's right yeah how is that Quantified in some way or how how do we know that it's typically Quantified through the governance side of a business so they say hey we have these procedures and policies we've measured business risk according to you know our business we know we know fraud for an example we know how X millions of dollars might be lost if this type of attack takes place and so we've introduced these controls and those controls are enforced by using this technology and so if we see that actually reducing that risk uh then we know that we have a return on investment okay uh Brandon a lot of good stuff uh thank you very much for sharing your experti today thanks for having me it was a pleasure great

This transcript was generated automatically from the video's captions and may contain errors.

Written By
James Maguire
James Maguire
Published: May 30, 2024
Updated: Sep 27, 2024
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

I spoke with Brandon Hoffman, Chief Strategy Officer at Intel 471, about the challenges and advantages of operationalizing threat intelligence.

James Maguire

James Maguire has been reporting on emerging technology for more than 15 years. He has won two ASBPE Awards of Excellence for in-depth feature articles about cloud computing and artificial intelligence. He has covered the gamut of enterprise and consumer technology, and regularly communicates with leading IT newsmakers, vendors and analysts.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.