Intel Node
Beyond IOCs: AI-enabled threat intelligence
Source excerpt · The upstream feed supplied only part of this article.Read the original source →
In this week’s newsletter, Martin considers how AI will help threat intelligence by creating an easily queryable data source of intelligence reports.
Welcome to this week’s Threat Source newsletter.   The issue of AI in cybersecurity is often portrayed as a binary choice: either a force multiplier for our adversaries, or a tool bringing professional obsolescence. The reality is more nuanced. While AI certainly brings some advantage to attackers, it also offers advantages to the defender, notably in how we manage, index, and derive value from threat intelligence.   Currently, our industry excels in the use and dissemination of indicators of compromise (IOCs).
These atomic indicators fit neatly into key-value data stores and their value can be enhanced with added context, neatly structured in STIX/MISP format.