The depreciation life cycle
An important part of defining a pattern of life for data is understanding how to handle transitioning something from "important" to "unimportant" or more specifically, a path to go from being "very important" to "less important."
The process to transition data has a few different names and I've distilled them down into the three most prevalent in order of concept, action, and process:
- Indicator decay (concept)
- Shunning (action)
- Deprecation pipeline (process)
Indicator decay
Decaying indicators is the concept or idea that indicators have a shelf life and must move from "top-priority" alerting to a lower threat or confidence. If every indicator stays at the same level of threat, responders and hunters will eventually be analyzing the entire internet because, while slight hyperbole, almost every atomic indicator will be flagged as a threat at some point.
The idea is that an indicator...