Intel
12 min
the intel tab in threat flow gathers all of your intelligence in one place, where you can review the latest reports from flare, create your own, and download any of them for further research there are two types of intel flare intel available to all flare customers, flare intel covers specific themes and industry verticals it is vetted, updated, and published by flare's analysts, with new intel released almost every day custom intel custom intel lets you build your own intelligence from ongoing conversations on the dark web, scoped to what matters to your organization access to custom intel requires an add on please reach out to your csm for more information click through the following product tour to learn how to regularly receive intelligence relevant to your organization receiving flare intel you can stay up to date on flare intel in two ways, depending on whether you prefer to check in yourself or have updates delivered to you check the intel tab in threat flow for the latest reports subscribe to the flare intel newsletter by clicking configure flare intel here you can choose the themes and industries you are interested in and configure which addresses the newsletter is sent to there is no limit to how many you can add newsletters are sent every monday at 7 00am utc receiving custom intel custom intel lets you build your own intelligence from ongoing conversations on the dark web, scoped to what matters to your organization follow these steps to create a custom intelligence report from threat flow, view the intel tab click create custom intel and describe the intelligence you are looking for see custom intel prompt guide docid\ vx9cxfqqtc833vj yhbdp for best practices and examples click submit flare generates the report in a few minutes and shows an estimate of how long it will take to compile custom intel prompt guide the quality of a custom intel report depends on the prompt behind it use these ready to use prompts to get started, organized by use case pick a category, replace the text in brackets with your own details, and run the prompt threat landscape by industry provide a summary of the most critical cybersecurity trends affecting the \[industry] industry, focusing on emerging threats and systemic risks what threat actors are targeting the \[industry] industry in \[country]? ransomware trends impacting \[industry] in \[country/region] in the last 90 days regional threat monitoring recent cyberattacks and ransomware activity in \[country/region] provide all cyber incidents in \[year] for \[country] ransomware and threat actor tracking create a threat profile for \[group name], including ttps, recent victims, and targeted industries what are the five most active ransomware groups right now? recent \[group name] victims and activity vulnerability intelligence recently disclosed and actively exploited cves targeting \[industry] infrastructure, including vpn appliances, remote access tools, and network edge devices is there any evidence of exploit code or threat actor interest for \[cve id]? organization and brand monitoring are there any leaks, breaches, or discussions involving \[company name] or \[domain]? are there any leaked credentials related to \[domain/email]? what mentions of \[company] have appeared on telegram channels or the dark web? recurring briefings summary of key cybersecurity events in \[month] \[year] affecting \[industry] in \[country] provide references where possible emerging threat intelligence from the past 7 days for a weekly briefing phishing, fraud, and social engineering recent phishing campaigns and scams targeting \[industry] companies known fraud campaigns involving \[method] impersonation targeting \[sector/country] geopolitical and nation state threats recent cyberattacks originating from \[country] targeting \[sector/region] nation state actors targeting \[sector] what should we watch for? technical iocs and ttps for soc teams provide ttps and iocs for \[threat actor/campaign] which iocs are new or trending in attacks against \[industry]? mitre att\&ck techniques used by threat actors targeting \[industry] in \[country] tips for better results be specific combine industry, country, and time frame, for example ransomware in healthcare in the uk in the last 90 days ask for references add "provide references where possible" to the end of a prompt set a time window, such as "in the last 7, 30, or 90 days" or "in \[month] \[year] " automate your monitoring reuse recurring prompts daily or weekly for continuous coverage sharing custom intel to share custom intel, download it and send it to the relevant stakeholders in the intel tab, select the custom intel report you want to share it opens in the details pane on the right click the export intel icon in the top right of the report choose download as docx or download as pdf to download and share the report