What Can Threat Intel Teams Learn from Journalists? @FIRSTdotorg
What Can Threat Intel Teams Learn from Journalists?  @FIRSTdotorg
Uploaded August 2025 | Updated September 2026, 4 hours ago
Chris Horsley (Cosive, AU)

Chris Horsley is the CTO and one of the co-founders of Cosive, a cybersecurity and CTI specialist consultancy based in Australia and New Zealand with a particular focus on security operations, IR, CTI practices, and tooling. He also enjoys experimenting with LLMs and CTI data formats like STIX and MISP and how to visualise and represent CTI concepts better.

He also has a long background in the international CSIRT community, which spanned roles including open source intelligence gathering, vulnerability disclosure handling, software and tooling development, malware analysis, and joint initiatives for national CSIRTs. Chris has previously worked as a security analyst for AusCERT, the national CSIRT at that time, and JPCERT/CC, the Japanese national CSIRT.
--
Cyber threat intelligence (CTI) attracts a lot of fancy frameworks and terminology, often coming from military intelligence. In spite of this, we often see CTI packages in feeds and sharing communities listing a few IPs addresses with very little context about their exact nature. If we find one of these IPs in our environment, so what? Will the CTI report tell us what we're dealing with?Let's get back to fundamentals and remove all the specialist language: what makes a CTI report actually useful? What does it need to do and who are we writing it for?There's something we all learned in primary school English classes that can help us write better CTI reports: how to write a newspaper article. If we get into the headspace of a reporter verifying their sources, thinking about their audience, and including the who, what, when, where, why, and how translated into cyber threats, we can improve the standard of CTI packages than a lot of what we see shared today.In this presentatation, we'll use this approach from first principles for making better CTI packages using MISP and STIX as well as something better for the humans in our constituency.
What Can Threat Intel Teams Learn from Journalists?The Myth of the Meteoric Rise in VulnerabilitiesSeeing Through the Fog: Interpreting Entra ID Signals During AiTM AttacksBreaking the SIEM ConfinementHunting Cyber Threat Intelligence on TelegramCyber Deception 2.0: Adaptive Honeynets and Canary Intelligence in ProductionWhats New in CSAF v2.1: Key Updates ExplainedArcana: A Unified Framework for Incident Response Documentation and Knowledge ManagementFrom Discovery to Fix: What 10,000 Open Source Projects Reveal About CVE RemediationLightning Talks!Anti-Forensics - You are Doing it Wrong (Believe Me, Im an IR Consultant)What Can Cybersecurity Incident Responders Learn from Real-World Crises?
FIRST |

What Can Threat Intel Teams Learn from Journalists?

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER