Say incident response to 10 people and odds are you'll get 10 different opinions on how to do it right. It's become common knowledge that the best threat intel comes from inside an organization but what threat intel is important and what is simply noise? What is going to cause the adversary the most pain? In this talk we'll review common threat intelligence artifacts, where they come from and how to craft IOCs for maximum effect for your IR efforts