Threat intelligence feeds
At a certain point, it will become obvious that no group of intel analysts can be experts in all the things that are constantly evolving in the intelligence community. There is simply too much information out there for any single group of individuals to be constantly up to date on the evolving threat landscape. Therefore, it is very important to ensure that the team is able to use targeted threat intelligence feeds and products.
There are numerous free and paid intelligence products on the market for individuals or organizations to subscribe to. Each can result in materials such as monthly or quarterly threat reports for the entire cybersecurity community, databases that can be queried, summaries of threat actor discussions on forums, and even live feeds that can be ingested into an organization's SIEM or network defenses for near real-time correlation of activities and increased protection. Similar to the rule of thumb for logging, intelligence is...