The Intelligence Team prioritizes threats that matter to our customers. Our customers face many threats, and we are not able to focus on all of them. We primarily focus on threats we are observing across many customers based on our own events and detections. We also consume external sources (such as reading blog posts, reviewing Twitter, and analyzing VirusTotal samples) and keep an eye on the threats that others are observing. When we identify a threat that we assess is of significant concern to customers, we create a profile for it based on both our internal sources as well as external sources. We often create a profile with minimal information and iteratively add to it over time. Transparency is a core value at Red Canary, and as such, we decided to be open about what we know—and don’t know—about threats.