| A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | ||||||||||||||||||||||||||
2 | Feedly Prioritized IR Blueprint: Example | |||||||||||||||||||||||||
3 | Want help populating blueprint? Conact your Feedly Threat Intelligence Advisor or read our IRs Guide | Stakeholders | Intelligence Dissemination | |||||||||||||||||||||||
4 | Steps: 1) Download a copy 2) Add in your own IRs, Stakeholders, and Intelligence Dissemination 3) Set up AI Feeds in Feedly to collect insights on your IRs | CISO Office | VM | SOC | Incident Response | Threat Hunting | Newsletter | Weekly Briefing | Flash Report | Monthly Intel Report | Trends Report | TIP | SIEM | Ticketing System | MSFT Teams or Slack | |||||||||||
5 | ||||||||||||||||||||||||||
6 | ||||||||||||||||||||||||||
7 | IR# | Intelligence Requirements | Priority | Feedback | ||||||||||||||||||||||
8 | Collected September 2025 | |||||||||||||||||||||||||
9 | Threat Landscape | |||||||||||||||||||||||||
10 | IR1.1 | Which adversaries are actively targeting our organization? | HIGH | CISO: monthly reports helped with budget decisions re DDoS protection | ||||||||||||||||||||||
11 | IR1.2 | What cyberattacks are currently affecting our sector? | MED | VM: need more intel on which adversaries are explioting CVEs in our tech stack | ||||||||||||||||||||||
12 | IR1.3 | Which types of attacks are trending up this month? | LOW | Threat Hunting: YARA and Sigma rules on trending attacks are useful, share more | ||||||||||||||||||||||
13 | ||||||||||||||||||||||||||
14 | Vulnerabilities | |||||||||||||||||||||||||
15 | IR2.1 | Have any high-severity vulnerabilities been disclosed today that could impact our tech stack? | HIGH | VM: Teams messages have been more effective than tickets, enabling faster response IR: Flash Reports timing has been efficient recently, 9/10 | ||||||||||||||||||||||
16 | IR2.2 | What zero-day vulnerabilities affecting our sector are currently being exploited? | MED | SOC: Need faster alerts when new zero-days drop, current 48hr delay too slow | ||||||||||||||||||||||
17 | IR2.3 | Which vulnerabilities impacting our suppliers have publicly available proof-of-concepts? | HIGH | Risk Management: Supplier risk assessments now include these IR insights, very valuable Procurement: Using this intel to adjust vendor security requirements in contracts | ||||||||||||||||||||||
18 | ||||||||||||||||||||||||||
19 | Malware | |||||||||||||||||||||||||
20 | IR3.1 | What new malware strains have emerged that could impact our organization? | LOW | Endpoint Security: Malware family analysis helped tune our EDR rules, 8/10 effectiveness | ||||||||||||||||||||||
21 | IR3.2 | What initial access methods are being used in current ransomware campaigns targeting our industry? | HIGH | IR: Access method intelligence reduced investigation time by 50%, great tactical value | ||||||||||||||||||||||
22 | IR3.3 | What IOCs are associated with the latest Remote Access Trojans? | MED | SOC: RAT C2 domains blocked proactively, prevented 3 infections last month | ||||||||||||||||||||||
23 | ||||||||||||||||||||||||||
24 | Adversary Activity | |||||||||||||||||||||||||
25 | IR4.1 | What are the latest TTPs being used by adversaries targeting our sector? | HIGH | Threat Hunting: Flash reports with novel TTPs have been highly effective, resulted in 4 new hunts | ||||||||||||||||||||||
26 | IR4.2 | How are adversaries using artificial intelligence to enhance their phishing attacks? | LOW | Security Awareness: Used examples in training, employee reporting up 40% | ||||||||||||||||||||||
27 | IR4.3 | What YARA and Sigma rules are available to detect adversary intrusions from the latest attacks? | HIGH | Threat Hunting: Have seen a decline in YARA and Sigma rule sharing, can we increase sources? | ||||||||||||||||||||||
28 | ||||||||||||||||||||||||||
29 | Emerging Threats | |||||||||||||||||||||||||
30 | IR5.1 | How is deepfake technology enabling cyberattacks this quarter? | LOW | Brand Protection: Deepfake detection tools deployed after Q2 intelligence briefing Legal: Intelligence helped draft new policies for synthetic media incident response | ||||||||||||||||||||||
31 | IR5.2 | How are adversaries leveraging cloud infrastructure to attack our sector? | MED | DevSecOps: Used tactics to harden our container deployment pipeline | ||||||||||||||||||||||
32 | ||||||||||||||||||||||||||
33 | Geopolitical Risks | |||||||||||||||||||||||||
34 | IR6.1 | How are Russian state-sponsored actors targeting critical infrastructure in our region? | MED | CorpSec: Targeting patterns help prioritize critical asset protection | ||||||||||||||||||||||
35 | IR6.2 | What cyberattacks are hacktivist groups launching in response to current geopolitical events? | LOW | Threat Hunting: Somewhat useful for hunt hypothesis, need more TTPs | ||||||||||||||||||||||
36 | ||||||||||||||||||||||||||
37 | ||||||||||||||||||||||||||
38 | ||||||||||||||||||||||||||
39 | ||||||||||||||||||||||||||
40 | ||||||||||||||||||||||||||
41 | ||||||||||||||||||||||||||
42 | ||||||||||||||||||||||||||
43 | ||||||||||||||||||||||||||
44 | ||||||||||||||||||||||||||
45 | ||||||||||||||||||||||||||
46 | ||||||||||||||||||||||||||
47 | ||||||||||||||||||||||||||
48 | ||||||||||||||||||||||||||
49 | ||||||||||||||||||||||||||
50 | ||||||||||||||||||||||||||
51 | ||||||||||||||||||||||||||
52 | ||||||||||||||||||||||||||
53 | ||||||||||||||||||||||||||
54 | ||||||||||||||||||||||||||
55 | ||||||||||||||||||||||||||
56 | ||||||||||||||||||||||||||
57 | ||||||||||||||||||||||||||
58 | ||||||||||||||||||||||||||
59 | ||||||||||||||||||||||||||
60 | ||||||||||||||||||||||||||
61 | ||||||||||||||||||||||||||
62 | ||||||||||||||||||||||||||
63 | ||||||||||||||||||||||||||
64 | ||||||||||||||||||||||||||
65 | ||||||||||||||||||||||||||
66 | ||||||||||||||||||||||||||
67 | ||||||||||||||||||||||||||
68 | ||||||||||||||||||||||||||
69 | ||||||||||||||||||||||||||
70 | ||||||||||||||||||||||||||
71 | ||||||||||||||||||||||||||
72 | ||||||||||||||||||||||||||
73 | ||||||||||||||||||||||||||
74 | ||||||||||||||||||||||||||
75 | ||||||||||||||||||||||||||
76 | ||||||||||||||||||||||||||
77 | ||||||||||||||||||||||||||
78 | ||||||||||||||||||||||||||
79 | ||||||||||||||||||||||||||
80 | ||||||||||||||||||||||||||
81 | ||||||||||||||||||||||||||
82 | ||||||||||||||||||||||||||
83 | ||||||||||||||||||||||||||
84 | ||||||||||||||||||||||||||
85 | ||||||||||||||||||||||||||
86 | ||||||||||||||||||||||||||
87 | ||||||||||||||||||||||||||
88 | ||||||||||||||||||||||||||
89 | ||||||||||||||||||||||||||
90 | ||||||||||||||||||||||||||
91 | ||||||||||||||||||||||||||
92 | ||||||||||||||||||||||||||
93 | ||||||||||||||||||||||||||
94 | ||||||||||||||||||||||||||
95 | ||||||||||||||||||||||||||
96 | ||||||||||||||||||||||||||
97 | ||||||||||||||||||||||||||
98 | ||||||||||||||||||||||||||
99 | ||||||||||||||||||||||||||
100 | ||||||||||||||||||||||||||