- What operating model does the paper describe?
- Intake, behavior extraction, binding to the stack, production, and expiry, the model Attack Nemesis uses with customers. It turns a backlog of tickets named after reports into a pipeline. Attack Nemesis turns finished intelligence into detections with owners, evidence, and retirement dates.
- Who is this paper for?
- Detection engineers and CTI leads whose backlog is a pile of tickets named after reports. It is a 31-page PDF brief with the conversion method in full. Attack Nemesis wrote it for teams converting intel into production detections.
- What should I show a CISO instead of "IOCs shipped"?
- The scorecard included in the paper, designed to replace a count of IOCs shipped with a view a CISO can act on. Attack Nemesis recommends reporting what intelligence changed, not how much of it arrived.
- What happens to a detection when its intelligence ages out?
- It retires on schedule. Expiry is the last step of the model, so detections do not pile up as ownerless rules. In Attack Nemesis, every detection carries a retirement date.