The best threat intelligence comes from your own
organization’s own endpoints. One aspect
to this is treating every instance of unwanted software such as malware or
adware that lands and installs on a machine as an indicator of a gap in
controls coverage.
A control that is present but somehow misconfigured.
A control that is missing or has been disabled.
An error by a user.
So, when you encounter evidence of malware, a key followup
item is to determine just how the malware got there.

















