Uploaded June 2026 | Updated September 2026, 3 hours ago
JJ Josing (Retail & Hospitality ISAC, US)
In an intelligence sharing community, the value of cyber threat intelligence depends on more than just what members contribute. It also relies on how that data is enriched, refined, and turned into actionable insights. This session will share practical methods for transforming raw indicators into high-quality intelligence using PyOTI as the enrichment and vetting engine.
Drawing from three years of experience managing the Retail & Hospitality ISAC’s community MISP instance, the talk will highlight ways to normalize multi-source enrichment, apply consistent tagging, and automate curation to reduce noise while keeping valuable context. Attendees will learn how to identify known bad and known good indicators, tune enrichment workflows, and build tagging practices that reduce alert fatigue and false positives. The session will close with simple, proven steps teams can take to improve the quality and reliability of shared intelligence.
---
JJ Josing is an open-source enthusiast with a passion for automation. He is RH-ISAC’s Principal Threat Researcher and has spent over seven years in cybersecurity within the retail industry. In his current role, JJ develops original threat research driven by member needs and oversees the management of indicators of compromise. He has also advanced and scaled the RH-ISAC’s sharing environments, supporting the growth of the member community and improving how intelligence is shared, enriched, and operationalized.
JJ Josing (Retail & Hospitality ISAC, US)
In an intelligence sharing community, the value of cyber threat intelligence depends on more than just what members contribute. It also relies on how that data is enriched, refined, and turned into actionable insights. This session will share practical methods for transforming raw indicators into high-quality intelligence using PyOTI as the enrichment and vetting engine.
Drawing from three years of experience managing the Retail & Hospitality ISAC’s community MISP instance, the talk will highlight ways to normalize multi-source enrichment, apply consistent tagging, and automate curation to reduce noise while keeping valuable context. Attendees will learn how to identify known bad and known good indicators, tune enrichment workflows, and build tagging practices that reduce alert fatigue and false positives. The session will close with simple, proven steps teams can take to improve the quality and reliability of shared intelligence.
---
JJ Josing is an open-source enthusiast with a passion for automation. He is RH-ISAC’s Principal Threat Researcher and has spent over seven years in cybersecurity within the retail industry. In his current role, JJ develops original threat research driven by member needs and oversees the management of indicators of compromise. He has also advanced and scaled the RH-ISAC’s sharing environments, supporting the growth of the member community and improving how intelligence is shared, enriched, and operationalized.










