Now that we've all seen an 'intelligence' stream, we can safely say it's not doing much. Rather than provide the statistical evidence of just how much it's not doing, this talk will discuss how to combine intelligence data with other data sources to answer questions such as "Is this new IP not in my intelligence data malicious?" and "Is this domain admin evil or just misguided?