threat-intelligence
1 post · all writing
Threat intelligence in a build pipeline: useful only when it is narrow
Most threat-intel feeds are a firehose aimed at a SOC, and pointing one at a CI job produces noise nobody actions. Scoped to the specific hosts and images you already declared, the same data answers a question no scanner can: what has the outside world already observed about this?