An intelligence-powered approach to threat intelligence investigations
Download resourcesAbout this session
David Ahn of Centripetal presents findings from what he describes as an academic, peer-reviewed study analyzing over 300 commercial, open-source and government cyber threat intelligence (CTI) providers. His team tracked roughly 10 billion active indicators and found that overlap between providers is only about 2 to 5%, that 66% of commercial intelligence is closed to outside use, and that 16% of indicators carry conflicting threat context between sources. A time-series analysis of 2023 CVEs shows that peak intelligence coverage of a new vulnerability typically takes around 15 days to build, yet roughly 75% of the indicators eventually attributed to an exploit were already known up to 90 days earlier under different or no attribution, meaning most breaches involve information that existed but was not accessible or connected in time. Ahn argues this fragmentation, driven by commercial differentiation rather than technical limits, explains why reactive, context-heavy threat hunting misses so much. He proposes shifting intelligence use further left on the MITRE ATT&CK kill chain, accepting lower-confidence indicators to reduce log volume proactively, and matching the intelligence quality demanded to actual business risk rather than treating every alert as needing full attribution.
An exploration of how an intelligence-powered approach to threat intelligence investigations, analyzing over 300 sources, can reveal statistics and insights that hint at measuring effectiveness in stopping and preventing attacks at the source.
Key takeaways
- Do not rely on a single threat intelligence provider; overlap between providers averages only 2-5%, so a small provider set gives partial coverage at best.
- Expect a coverage gap of roughly two to fifteen days after a new CVE is disclosed before intelligence providers catch up; plan compensating controls for that window.
- Match the confidence and context you demand from an indicator to actual business risk, not a fixed standard; low-risk assets can tolerate lower-confidence blocks.
- Shift intelligence use earlier in the MITRE ATT&CK kill chain (toward reconnaissance and delivery) to cut log volume proactively rather than only hunting after the fact.
- Close the loop from investigation reports back into blocking and detection rules; a report that is not fed back into the SIEM or shielding posture is wasted work.
Speakers

Currently the Chief Architect and VP at Centripetal, Ahn is a technology innovator in informatics, security and privacy. He has been awarded patents in both cybersecurity and healthcare which served as foundations for the growth of his endeavors… Read moreRead less
Currently the Chief Architect and VP at Centripetal, Ahn is a technology innovator in informatics, security and privacy. He has been awarded patents in both cybersecurity and healthcare which served as foundations for the growth of his endeavors. Prior to joining Centripetal, he held leadership roles at two technology-transfer startups that commercialized breakthrough research into successful outcomes.
