Hack the Gap - Closing the CTI Divide Between Small Teams and Big Players
Chandler McClellan
Security Fest 2025 · Day 2 · Main Stage
Overview
In the contemporary cybersecurity landscape, the disparity in threat intelligence capabilities between large enterprises and smaller organizations presents a critical challenge. This talk, "Hack the Gap - Closing the CTI Divide Between Small Teams and Big Players," delivered by Chandler McClellan at Security Fest, directly addresses this imbalance. McClellan, a Senior Consultant at Coalfire specializing in dark web monitoring, threat intelligence, and threat hunting, offers practical strategies and insights for small security teams to develop robust Cyber Threat Intelligence (CTI) programs without the extensive resources available to industry giants.

Key moments
- 0:00 Talk introduction and Security Fest welcome
- 1:30 Speaker's professional background and experience
- 2:20 Defining the CTI divide: Small vs. Large teams
- 4:40 Why CTI is a force multiplier for small teams
- 5:15 CTI industry adoption and growing trends
- 6:05 CTI: No longer a 'nice-to-have,' but essential
- 6:30 Diverse value-add and uses of CTI
Hack the Gap - Closing the CTI Divide Between Small Teams and Big Players
Speakers: Chandler McClellan
Conference: Security Fest
YouTube: https://www.youtube.com/watch?v=Znl7TBFAz9E
Overview
In the contemporary cybersecurity landscape, the disparity in threat intelligence capabilities between large enterprises and smaller organizations presents a critical challenge. This talk, "Hack the Gap - Closing the CTI Divide Between Small Teams and Big Players," delivered by Chandler McClellan at Security Fest, directly addresses this imbalance. McClellan, a Senior Consultant at Coalfire specializing in dark web monitoring, threat intelligence, and threat hunting, offers practical strategies and insights for small security teams to develop robust Cyber Threat Intelligence (CTI) programs without the extensive resources available to industry giants.
The core premise of the presentation is that while large corporations like FANG companies (Facebook, Apple, Amazon, Netflix, Google) invest millions in dedicated CTI teams, advanced tools, and vast budgets, smaller organizations face the same sophisticated threats—including nation-state actors and cybercriminals—with significantly fewer resources. This talk is crucial because it provides a roadmap for these under-resourced teams to leverage Open Source Intelligence (OSINT), automation, structured processes, and collaboration to achieve impactful, high-quality CTI.
The importance of this topic cannot be overstated. Threat actors indiscriminately target organizations of all sizes, with over half of malware attack victims being small businesses. CTI is not merely a "nice-to-have" but a vital force multiplier, with 87% of organizations reporting that it improves their prevention, detection, and response capabilities. McClellan's talk empowers small teams to overcome common inhibitors like limited budgets, skills gaps, and lack of management buy-in, ensuring they can effectively defend against an ever-evolving threat landscape.
Background
▶ Watch: Talk introduction and Security Fest welcome (0:00)
The landscape of cyber defense is starkly divided. On one side stand large enterprises, equipped with dedicated CTI teams, expansive budgets, and cutting-edge tools. These organizations, as McClellan vividly describes, are "100 gorillas" against the "one single human" that represents a small team. In contrast, smaller organizations often operate with minimal or no full-time CTI staff, constrained budgets, and a lack of specialized tools. This fundamental disparity creates a significant vulnerability, as threat actors do not discriminate based on organizational size, frequently targeting smaller entities that are less prepared.
The business impact of this gap is substantial, leading to slower detection and response times, undetected breaches, costly incidents, and strategic blind spots for small teams. The SANS CTI Survey 2024, cited by McClellan, highlights the growing recognition of CTI's importance: over half of organizations had clearly defined threat intelligence requirements in 2023, and only 3% had no plans for CTI adoption. This indicates a universal understanding of CTI's value, yet the resource divide persists. Leadership, too, is increasingly on board, with over half of executives recognizing the measurable effect of actionable CTI at an organizational level.
To bridge this gap, a foundational understanding of CTI is essential. McClellan defines CTI as "analyzed information about adversaries that informs cybersecurity decision making." Critically, it is not raw data, IP addresses, or fancy APT reports; it is the process of transforming raw data into contextualized, actionable intelligence that informs security controls and strategy. CTI operates at three distinct levels:
- Strategic CTI: High-level, big-picture insights for executive decision-makers.
- Operational CTI: Focuses on specific campaigns, adversary tactics, and activity clusters.
- Tactical CTI: Provides immediate, technical indicators of compromise (IoCs) for security analysts and tools.
Effective CTI relies on a cyclical process known as the Intelligence Cycle, which includes:
- Direction: Defining requirements and priorities (what do we need to know?).
- Collection: Gathering relevant data from logs, OSINT, threat feeds, etc.
- Processing: Cleaning, organizing, enriching, and structuring data for usability. This is often one of the toughest steps, with many competing solutions and no single solved problem.
- Analysis: Interpreting data to derive meaning and produce intelligence outputs.
- Dissemination: Sharing finished intelligence with the right stakeholders (SOC analysts, management) in appropriate formats (reports, dashboards, lists).
- Feedback: Evaluating the value and effectiveness of disseminated intelligence to refine future efforts. Skipping this step can lead to producing "frustrating to use or broken or incomplete intelligence."
Beyond the cycle, understanding adversary behavior is crucial, often guided by established models. McClellan discusses three key models, noting Scott Roberts' quote: "All models are wrong. Some are useful." These models provide a standardized way to communicate and analyze threats:
- Cyber Kill Chain: Lockheed Martin's seven-stage model (reconnaissance to actions on objectives) helps defenders identify where an attack is detected and can be stopped. It's useful for highlighting defensive gaps.
- Diamond Model of Intrusion Analysis: A relationship-based model focusing on adversaries, victims, capabilities, and infrastructure. It's effective for analyzing specific incidents and campaigns, helping to piece together the puzzle of an intrusion.
- MITRE ATT&CK TTPs: The most popular model, providing a globally accessible knowledge base of adversary tactics, techniques, and procedures. Small teams can map observed activity to ATT&CK to understand who they might be facing, anticipate next moves, and identify areas for improved detection and defense.
The primary challenges inhibiting small teams from establishing effective CTI programs include limited budget (the number one inhibitor), skills gap (lack of experienced analysts or training resources), and management buy-in (securing the necessary time and resources). Addressing these foundational elements is critical for any small organization aspiring to build a robust CTI capability.
Key Findings
▶ Watch: Defining the CTI divide: Small vs. Large teams (2:20)
The talk "Hack the Gap" presents a clear mission: to empower small security teams to achieve impactful and high-quality CTI without requiring FANG-level resources. Chandler McClellan outlines several key strategies to bridge this divide, emphasizing efficiency, leveraging available resources, and strategic implementation.
The overarching finding is that by focusing on specific, actionable areas, small teams can punch above their weight. The four core strategies identified are:
- Optimizing Open Source Intelligence (OSINT): OSINT is highlighted as the "lifeblood" of intelligence for budget-constrained organizations. It's free or low-cost, abundant, and widely used across the industry (69% of CTI teams, including large players, incorporate open feeds). The key is efficient and effective collection and filtering to extract true signal from noise.
- Automation: Given the limited personnel in small teams, automation is presented as crucial for scaling CTI efforts. It frees up precious analyst time from manual, repetitive tasks, allowing them to focus on higher-level analytical work and connecting the dots.
- Turning Data into Actionable Insights: Raw data, regardless of how it's collected, is not intelligence. The talk stresses the importance of structured processes, frameworks, and methodologies to analyze data, derive meaning, and ensure that the intelligence produced is directly relevant and actionable for the organization. This includes applying the "So What" test to every piece of potential intelligence.
- Fostering Collaboration: Both internal and external collaboration are presented as force multipliers. Sharing intelligence and working with others, even competitors, can significantly amplify a small team's capabilities and provide a collective defense against common threats.
In essence, the talk finds that small teams can overcome resource limitations by being deliberate and strategic in their approach to CTI. This involves a heavy reliance on publicly available information, smart application of technology to automate mundane tasks, a rigorous process for analysis and contextualization, and a willingness to engage with broader security communities. The speaker also implicitly finds that while commercial threat intelligence platforms exist, open-source or more flexible solutions like MISP, OpenCTI, and especially Synapse can provide comparable value when properly implemented.
Technical Deep Dive
▶ Watch: Why CTI is a force multiplier for small teams (4:40)
The technical deep dive into closing the CTI gap for small teams revolves around three pillars: effective OSINT, strategic automation, and structured analysis leading to actionable insights, all within a collaborative framework.
Leveraging Open Source Intelligence (OSINT)
OSINT is presented as the "lifeblood" for small, budget-constrained organizations. It encompasses publicly available information that, when analyzed, yields valuable threat intelligence. This includes a vast array of sources such as threat research blogs, vendor reports, social media, dark web forums, vulnerability databases, and malware repositories. The challenge for small teams is not a lack of data, but rather knowing where to look and how to filter the "true signal from all the noise."
McClellan advises a focused approach:
- Requirement-Driven Collection: Don't drown in data. Guide collection with specific intelligence requirements. For example, a fintech startup should prioritize OSINT related to financial services threats, relevant CVEs, and threat actor groups targeting finance.
- Curated Source Lists: Build a list of trusted, reliable sources like industry ISACs, security bulletins, and open alerts.
- Free and Low-Cost Tools: Utilize tools like Spyse (for domain/IP intelligence), Maltego Community Edition (for link analysis), Shodan (for internet mapping), and even Google Dorks for finding reports.
- Validation and Enrichment: OSINT is not all equal. Cross-verify critical information, especially before making decisions. Enrich raw indicators (e.g., hashes, IPs) by querying services like VirusTotal or Open Threat Exchange reports to add context and identify known malicious associations. This helps confirm if a suspicious domain in firewall logs is tied to a known phishing kit.
- Crowdsourcing Intelligence: Actively engage with intelligence communities. Many groups, including those of competitors, share threat information through "Fight Club" style advisories, offering early warnings about IPs or activity. This reciprocity is crucial for collective defense.
Strategic Automation
Automation is paramount for small teams to maximize efficiency and elevate their CTI capabilities. It frees up analysts from manual, repetitive tasks, allowing them to focus on higher-level analytical work.
Key areas for automation include:
- Data Collection: Develop simple scripts or use APIs to automatically pull data from established threat intelligence feeds or vendor reports.
- Data Processing: Automate the parsing of reports to extract indicators. For instance, a script can monitor a vendor's feed, download new reports, and automatically parse out relevant data, preparing it for analysis.
- Enrichment: Set up automated workflows to send collected indicators (hashes, IPs) to external APIs that return additional context. This can quickly identify if a hash is associated with known malware or if an IP is linked to a specific campaign.
- Practical Examples:
- Threat Intelligence Feed Triage: Automatically push IoCs from trusted feeds into IPS/IDS or firewall rules. This can block known malicious traffic (e.g., random connections from Russia) without manual intervention.
- Phishing Email Analysis: Automate the submission of suspicious emails to a sandbox for analysis, receiving results back without an analyst having to manually initiate the process each time.
McClellan emphasizes that these automations don't require expensive SOAR platforms or dedicated developers. Python is a perfectly capable tool, and many free tools and APIs with free tiers exist for these purposes. Even Large Language Models (LLMs) can be "gaslit" into writing scrapers for PDFs to extract indicators. The goal is to "cobble together" solutions that are efficient and effective.
From Data to Actionable Insights
The transformation of collected data into actionable intelligence is a critical analytical step. As McClellan stresses, "data is not intelligence."
- Prioritization through Context: Always ask: "What's the goal? What's the problem you're trying to solve?" This contextual lens helps prioritize analysis.
- Frameworks for Identification: Use frameworks like MITRE ATT&CK to map observed activity. If a defense evasion column in an ATT&CK heat map is consistently empty, it may indicate a visibility gap. This standardization helps identify who an organization might be facing and anticipate next moves.
- Scalable Intel Processes: Establish lightweight review cycles (daily, weekly) for triaging new intel, performing analysis, and disseminating findings. Don't wait for a "fully flushed out program" to start sharing intelligence; early feedback is invaluable for continuous improvement.
- The "So What" Test: For every piece of intelligence, ask, "So what does this mean for us?" If the answer isn't immediately clear, either dig deeper or deprioritize it. This ensures relevance and prevents wasted time on interesting but non-impactful information (e.g., "cool fancy Chinese hackers" that don't target the organization's vertical).
Fostering Collaboration
CTI is inherently a team sport, requiring extensive collaboration both internally and externally.
- Internal Collaboration: Regularly interface with internal teams such as vulnerability management, SOC analysts, and incident response (IR) teams. Share intelligence, discuss findings, and ensure alignment. This also helps secure continued management buy-in by demonstrating value.
- External Collaboration: Join general information-sharing communities. Many small organizations team up to share what they're seeing, creating a "strength in numbers" effect. Embrace reciprocity—sharing information, even with direct competitors in the same sector, can lead to mutual benefits as they likely face similar threats.
CTI Platforms
As intelligence collection grows, a dedicated platform becomes essential for storage, organization, and analysis. McClellan briefly compares three prominent options:
- MISP (Malware Information Sharing Platform): Widely used, open-source, focused on sharing IoCs and collaboration. It's simple but has an older user experience and can be complex to configure and scale.
- OpenCTI: A newer, more modern platform with richer data modeling (using STIX and TAXII), a nicer UI, and strong community support for integrations. However, it can be complex to deploy and is hardware-intensive due to its graph database approach.
- Synapse: The speaker's "game changer" recommendation. Developed by the Vertex Project (out of Mandiant), it offers a highly flexible data model that allows tagging and linking complex relationships, facilitating natural analysis. It features a powerful query language and "powerups" for automation. While it has a steeper learning curve and its open-source version is terminal-based (the nice UI is paywalled), its flexibility and scaling potential make it a strong choice for complex intel needs.
In summary, the technical approach emphasizes smart, targeted use of free resources, automation to multiply human effort, and structured analytical processes, all underpinned by a collaborative mindset and supported by appropriate CTI platforms to manage the growing volume of intelligence.
Demo / Proof of Concept
▶ Watch: CTI: No longer a 'nice-to-have,' but essential (6:05)
While the talk did not feature a live, interactive demo in the traditional sense, Chandler McClellan provided a compelling overview and visual walkthrough of Synapse, an open-source central intelligence system, showcasing its capabilities as a powerful tool for small teams. He positioned Synapse as a "game changer" for organizations needing complex intelligence needs that scale well over time, even acknowledging that the open-source version operates primarily in the terminal, contrasting it with the paywalled GUI of the enterprise offering.
McClellan demonstrated how Synapse streamlines the intelligence workflow:
- Ingestion and Extraction: He showed how Synapse can ingest a "random cyber threat intelligence report." The platform automatically extracts key entities from the report, such as different threat groups, the report's origin, dates, specific malware names, and various activity sets. This eliminates the manual, tedious process of reading through PDFs and extracting indicators.
- Data Structuring and Tagging: Once extracted, Synapse automatically tags these pieces of information. This includes creating relationships and linking them together in a "highly flexible data model." This ability to connect disparate data points into complex relationships is what enables "really natural analysis for humans."
- Automated Enrichment and Analysis: The platform can then run various "scripts" or "powerups" against the extracted data. For example, it automatically checks hashes against known malware databases, queries IPs for malicious associations, and identifies connections to known campaigns. This mimics the manual "what the heck am I looking at?" process an analyst would perform, but in an automated and efficient manner.
- Visualization and Pivoting: Synapse facilitates understanding these relationships through "cool graphs," allowing analysts to "understand pivots" and explore connections within the data. This visual representation aids in uncovering hidden links and understanding the broader context of an adversary's activities.
- Automated Report Production: A significant benefit highlighted is Synapse's ability to help "produce reports just nice and automated." This capability addresses a common pain point for analysts who need to summarize their findings for management or other stakeholders without spending excessive time compiling data manually.
McClellan's presentation of Synapse serves as a strong proof of concept for how a small team, even with a "shoestring budget," can leverage sophisticated tooling to manage and analyze vast amounts of threat intelligence. He underscored that "we're not lazy, we're efficient and we love it," emphasizing that tools like Synapse enable efficiency by automating repetitive tasks, allowing analysts to focus on higher-value cognitive work. This walkthrough effectively demonstrated how Synapse can be a cornerstone for building a scalable and effective CTI program in resource-constrained environments.
Defensive Implications
▶ Watch: Diverse value-add and uses of CTI (6:30)
The insights shared in "Hack the Gap" offer critical defensive implications for small organizations striving to enhance their cybersecurity posture. The core message is that effective CTI is achievable without an exorbitant budget, provided teams adopt a strategic, incremental, and collaborative approach.
Defenders should immediately consider the following actions:
- Prioritize and Optimize OSINT: Recognize that OSINT is a goldmine for free or low-cost intelligence. Small teams should establish clear intelligence requirements to guide their OSINT collection, focusing on threats directly relevant to their industry and assets (e.g., a fintech startup monitoring financial services threats). Building curated lists of trusted sources (ISACs, vendor reports, reputable blogs) and leveraging free tools like VirusTotal, Open Threat Exchange, Maltego Community, Shodan, and Google Dorks can significantly enhance visibility. Crucially, all collected OSINT must be validated and enriched to ensure its quality and relevance, applying the "So What" test to every piece of information.
- Invest Wisely in Automation: Automation is not a luxury but a necessity for small teams to scale their CTI efforts. Defenders should identify repetitive, manual tasks in their intelligence workflow (e.g., data collection, parsing reports, indicator enrichment) and seek to automate them. This can be achieved using Python scripts, readily available APIs with free tiers, or even basic LLM-driven scrapers. Automating threat intelligence feed ingestion into IPS/IDS or firewall rules, or setting up automated sandboxing for suspicious emails, frees up analysts to focus on higher-level analysis and proactive threat hunting.
- Implement Structured CTI Processes: Data alone is not intelligence. Organizations must adopt structured processes based on the Intelligence Cycle (Direction, Collection, Processing, Analysis, Dissemination, Feedback) and leverage models like the Cyber Kill Chain, Diamond Model, and MITRE ATT&CK TTPs. These frameworks help standardize communication, identify defensive gaps, and ensure that intelligence is contextualized and actionable. Regular, lightweight review cycles for new intelligence, with early feedback mechanisms, are vital for continuous improvement.
- Foster Robust Collaboration: CTI is a team sport. Internally, defenders must actively collaborate with vulnerability management, SOC, and incident response teams to ensure intelligence informs immediate operational decisions and long-term strategy. Externally, joining information-sharing communities and practicing reciprocity with industry peers—even competitors—can significantly multiply defensive capabilities against common adversaries. Sharing observations and threat data can provide early warnings and enhance collective resilience.
- Adopt a Scalable CTI Platform: As intelligence collection grows, a dedicated platform becomes indispensable for organizing, storing, and analyzing data. While commercial solutions exist, small teams can leverage open-source options like MISP, OpenCTI, or the highly recommended Synapse. Synapse, with its flexible data model, powerful query language, and automation "powerups," can be a game-changer for managing complex threat data, even if its open-source version requires comfort with a terminal interface. The goal is to choose a platform that scales with the team's evolving needs and facilitates efficient analysis and reporting.
- Focus on Incremental Growth and Value Demonstration: Small teams should start with "quick wins" and incrementally build their CTI program. Prioritize "people, then processes, then tools," ensuring the foundational elements are in place. Consistently demonstrate the value added to the organization through CTI efforts to secure continued management buy-in and resources. Being pragmatic and avoiding over-ambitious goals, while continuously seeking feedback, will ensure the CTI program remains a beneficial asset rather than a burden.
By diligently implementing these defensive strategies, small organizations can significantly "hack the gap," moving beyond reactive defense to a proactive, intelligence-driven security posture that rivals, in effectiveness, some of their larger counterparts.
Key Takeaways
- OSINT is the Equalizer: For small teams with limited budgets, Open Source Intelligence (OSINT) is the most crucial resource, offering abundant, free, or low-cost data that, when effectively processed, can provide valuable threat intelligence.
- Automation is Essential for Efficiency: To overcome staffing limitations, small teams must strategically implement automation for data collection, processing, and enrichment, freeing analysts for higher-level analytical tasks and connecting the dots.
- Data is Not Intelligence: Raw data requires rigorous analysis, contextualization, and the application of frameworks (like MITRE ATT&CK) and the "So What" test to transform it into actionable intelligence relevant to the organization's specific threats.
- Collaboration Amplifies Capabilities: Both internal collaboration (with SOC, IR, VM teams) and external information sharing (with industry communities, even competitors) are vital for multiplying a small team's defensive capabilities and gaining early warnings.
- CTI Platforms are Critical for Scale: As intelligence grows, dedicated platforms like MISP, OpenCTI, or especially Synapse become necessary for organizing, analyzing, and disseminating threat data effectively, moving beyond manual spreadsheets.
- Start Small, Demonstrate Value, and Iterate: Build CTI programs incrementally, focusing on quick wins, demonstrating tangible value to management early on, and continuously seeking feedback to refine processes and tools.
About the Speaker(s)
Chandler McClellan is a recent university graduate who has quickly made a name for himself in the cybersecurity industry. He currently serves as a Senior Consultant at Coalfire, where his expertise spans dark web monitoring, threat intelligence, and threat hunting for a diverse range of clients. McClellan is passionate about the cybersecurity community and enjoys connecting with professionals at conferences. He candidly shares his journey, humorously noting that a mentor "forced" him into cybersecurity, a path he now embraces with enthusiasm, particularly in helping organizations build robust intelligence capabilities.