How can I provide feedback for GTI when it has misleading, confusing, or inaccurate assessments of IOcs.
E.g. Comcast v4 IP addresses are indicated as IOCs.
We’re testing some GTI-related rules in the SIEM and the results by volume are mostly nonsense. So filtering on our side is needed.
This is to be expected but some IOCs are obviously misleading,