Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Intelligence @FIRSTdotorg
Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Intelligence  @FIRSTdotorg
Uploaded June 2026 | Updated September 2026, 3 hours ago
JJ Josing (Retail & Hospitality ISAC, US)

In an intelligence sharing community, the value of cyber threat intelligence depends on more than just what members contribute. It also relies on how that data is enriched, refined, and turned into actionable insights. This session will share practical methods for transforming raw indicators into high-quality intelligence using PyOTI as the enrichment and vetting engine.

Drawing from three years of experience managing the Retail & Hospitality ISAC’s community MISP instance, the talk will highlight ways to normalize multi-source enrichment, apply consistent tagging, and automate curation to reduce noise while keeping valuable context. Attendees will learn how to identify known bad and known good indicators, tune enrichment workflows, and build tagging practices that reduce alert fatigue and false positives. The session will close with simple, proven steps teams can take to improve the quality and reliability of shared intelligence.

---

JJ Josing is an open-source enthusiast with a passion for automation. He is RH-ISAC’s Principal Threat Researcher and has spent over seven years in cybersecurity within the retail industry. In his current role, JJ develops original threat research driven by member needs and oversees the management of indicators of compromise. He has also advanced and scaled the RH-ISAC’s sharing environments, supporting the growth of the member community and improving how intelligence is shared, enriched, and operationalized.
Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared IntelligenceThe Convergence of Threat Behaviors Across IntrusionsForecasting Cybersecurity Data: Making Sense of the SenselessHow EPSS Is Wrong and Useful at the Same TimeWhy is Finnish Healthcare Doing So Well Against Ransomware?The Funny Story of Active Directory BackdooringPivoting To Resilience: Disruptive Incidents And How We Prepare For ThemLessons From NPMs Dark Side: Preventing the Next Shai-HuludThe CVE Blind Spot: Defeating Hidden EOLs and Repo Jacking with Engineering Triage & Code DietAll Ransomware Economic Models are Wrong, But This One is UsefulCISA-ENISA Joint MessagingPanel: From Takedown to Touchpoint: An Inside Look at the Data-sharing Pipeline in the Victim ...
FIRST |

Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Intelligence

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER