ABCDEFGHIJKLMNOPQRSTUVWXYZ
1
2
Feedly Prioritized IR Blueprint: Example
3
Want help populating blueprint? Conact your Feedly Threat Intelligence Advisor or read our IRs Guide
Stakeholders Intelligence Dissemination
4
Steps:
1) Download a copy
2) Add in your own IRs, Stakeholders, and Intelligence Dissemination
3) Set up AI Feeds in Feedly to collect insights on your IRs
CISO OfficeVMSOCIncident ResponseThreat HuntingNewsletterWeekly BriefingFlash ReportMonthly Intel ReportTrends ReportTIPSIEMTicketing SystemMSFT Teams or Slack
5
6
7
IR#Intelligence RequirementsPriorityFeedback
8
Collected September 2025
9
Threat Landscape
10
IR1.1Which adversaries are actively targeting our organization?HIGHCISO: monthly reports helped with budget decisions re DDoS protection
11
IR1.2What cyberattacks are currently affecting our sector?MEDVM: need more intel on which adversaries are explioting CVEs in our tech stack
12
IR1.3Which types of attacks are trending up this month?LOWThreat Hunting: YARA and Sigma rules on trending attacks are useful, share more
13
14
Vulnerabilities
15
IR2.1Have any high-severity vulnerabilities been disclosed today that could impact our tech stack?HIGHVM: Teams messages have been more effective than tickets, enabling faster response
IR: Flash Reports timing has been efficient recently, 9/10
16
IR2.2What zero-day vulnerabilities affecting our sector are currently being exploited?MEDSOC: Need faster alerts when new zero-days drop, current 48hr delay too slow
17
IR2.3Which vulnerabilities impacting our suppliers have publicly available proof-of-concepts?HIGHRisk Management: Supplier risk assessments now include these IR insights, very valuable
Procurement: Using this intel to adjust vendor security requirements in contracts
18
19
Malware
20
IR3.1What new malware strains have emerged that could impact our organization?LOWEndpoint Security: Malware family analysis helped tune our EDR rules, 8/10 effectiveness
21
IR3.2What initial access methods are being used in current ransomware campaigns targeting our industry?HIGHIR: Access method intelligence reduced investigation time by 50%, great tactical value
22
IR3.3What IOCs are associated with the latest Remote Access Trojans?MEDSOC: RAT C2 domains blocked proactively, prevented 3 infections last month
23
24
Adversary Activity
25
IR4.1What are the latest TTPs being used by adversaries targeting our sector?HIGHThreat Hunting: Flash reports with novel TTPs have been highly effective, resulted in 4 new hunts
26
IR4.2How are adversaries using artificial intelligence to enhance their phishing attacks?LOWSecurity Awareness: Used examples in training, employee reporting up 40%
27
IR4.3What YARA and Sigma rules are available to detect adversary intrusions from the latest attacks?HIGHThreat Hunting: Have seen a decline in YARA and Sigma rule sharing, can we increase sources?
28
29
Emerging Threats
30
IR5.1How is deepfake technology enabling cyberattacks this quarter?LOWBrand Protection: Deepfake detection tools deployed after Q2 intelligence briefing
Legal: Intelligence helped draft new policies for synthetic media incident response
31
IR5.2How are adversaries leveraging cloud infrastructure to attack our sector?MEDDevSecOps: Used tactics to harden our container deployment pipeline
32
33
Geopolitical Risks
34
IR6.1How are Russian state-sponsored actors targeting critical infrastructure in our region? MEDCorpSec: Targeting patterns help prioritize critical asset protection
35
IR6.2What cyberattacks are hacktivist groups launching in response to current geopolitical events?LOWThreat Hunting: Somewhat useful for hunt hypothesis, need more TTPs
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100