
NEW2CTI | Connecting the Dots: Incident to Campaign Intel
Source: YouTube · SANS Digital Forensics and Incident Response · published Apr 2, 2026 · 31:56
BLUF: The presentation outlines strategies for transforming raw incident data into actionable campaign intelligence, aiming to help teams, especially those new to intrusion analysis, effectively organize and analyze their security data 0:14.
Key Takeaways:
• The core goal is to bridge the gap between raw incident data and strategic intelligence, enabling teams to identify patterns and threats more effectively 0:17.
• The speaker shares internal processes and lessons learned developed over eight years in Cyber Threat Intelligence (CTI) to guide less experienced teams 0:46.
• The session focuses on practical methods for structuring data analysis to support better decision-making in intrusion detection and response 0:21.
This approach provides a foundational framework for organizations looking to mature their incident response capabilities through better data utilization.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Incident Response. Commonly maps to: Security Operations, Security Assessment and Testing. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
Pleasure to be here and speaking with you today. Hello to everyone that's joining online as well. Title of today's presentation is connecting the dots transforming incident data into actionable campaign intelligence. This is a presentation aimed at helping teams who are trying to understand, organize, and analyze their incident data by talking about the development of some of our own processes and some of the lessons that we've learned along the way, particularly if you or your teams are just getting started out in intrusion analysis. So, we'll start with some introductions before we get into the main theme and the agenda for today's talk. My name is Adam. I've been working in CTI for just over eight years now and I traveled over from the UK to be here today. Managed to beat the snowstorm …