@GossiTheDog Agree. There are good people doing threat intel and it can definitely be useful to know bad guys’ “MO” but I’ve been feeling uncomfortable too about what seems to be a focus on info gathering (and storytelling) at the cost of actually doing anything about what’s happening. I get the feeling we’ve given up on protecting individual users and small companies in favour of corporate clients who can afford expensive red team/blue team setups.