CypherCon 2026
Filtering the Noise: Crafting an Actionable Threat Feed from Community-Shared Intelligence
JJ Josing
Abstract:
In an intelligence sharing community, the value of cyber threat intelligence depends not only on what members contribute, but also on what the community can effectively enrich, refine and operationalize. This session presents practical and repeatable methods for transforming raw indicators into high-fidelity, threat intelligence using PyOTI as the enrichment and vetting engine.
Drawing from over three years of experience managing the Retail & Hospitality ISAC’s community MISP instance, this talk will showcase how to normalize multi-source enrichment, apply consistent attribute-level tagging, and implement automated curation workflows that reduce noise while preserving valuable context. We will explore how enrichment providers, custom taxonomies, and tagging logic can be combined to automatically identify both known bad (threats already with bad reputation, on a block list, etc.) and known good indicators (potential false positives like Outlook infrastructure or cmd.exe).
A key focus will be preventing low fidelity indicators from entering the operational pipeline. Attendees will learn how to tune enrichment requirements, establish trust signals, and develop community tagging conventions that reduce alert fatigue, such as handling often misused yet legitimate infrastructure without suppressing meaningful detections.
The talk will conclude with a set of practical recommendations teams can use to achieve consistent, repeatable enrichment, higher-quality vetted indicators, and a more stable flow of actionable intelligence without adding new commercial tools or overwhelming analysts.

JJ Josing
Retail & Hospitality ISAC, Principal Threat Researcher
JJ Josing is an open-source enthusiast with a passion for automation. He is RH-ISAC’s Principal Threat Researcher and has spent over seven years in cybersecurity within the retail industry. In his current role, JJ develops original threat research driven by member needs and oversees the management of indicators of compromise. He has also advanced and scaled the RH-ISAC’s sharing environments, supporting the growth of the member community and improving how intelligence is shared, enriched, and operationalized.