Skip to main content

Monitoring rules use cases—Cyber Threat Intelligence (CTI)

Monitoring rules are most effective when configured with your organization's specific context in mind. The following use cases illustrate how different industries and teams can configure rules to reduce noise and surface the threats that matter most to their environment.

Each example includes a suggested target audience, a recommended rule configuration, and a real-world scenario showing the rule in action. Use these as starting templates and refine the criteria based on your own technology stack, geography, and risk tolerance.


Financial Services & Fintech

Target audience

Security Analysts, Fraud Teams, CISOs

Financial institutions face a unique combination of high-value targets, regulatory scrutiny, and sector-specific threats. This rule configuration focuses on fraud schemes, payment system attacks, and threat actors known to target banks and fintech platforms.

Suggested rule configuration

  • Target industry: Finance and Insurance

  • Location: your primary operating region(s)

  • Types of threats: Ransomware, Data Breach, Malware

  • Terms: PIX, Open Banking, TED, SWIFT, wire transfer, card skimming (in English only)

  • Threat actors: known financially motivated groups such as FIN7, Lazarus

  • Risk level: High or Critical

Use case example

Maria leads threat intelligence at a mid-size Brazilian bank. Her monitoring rule combines Location: Brazil, Industry: Finance, and Terms: PIX and Open Banking. Within days of activating it, she receives an alert about a new malware campaign targeting PIX transaction APIs. Her team patches the vulnerable endpoint before any transaction is compromised.


Retail & E-commerce

Target audience

Security Operations, IT Risk, Fraud Prevention Teams

Retail environments are exposed to payment fraud, credential stuffing, and seasonal attack spikes around high-traffic periods like Black Friday and Cyber Monday. Rules for this sector benefit from time-aware terms and e-commerce platform coverage.

Suggested rule configuration

  • Target industry: Retail and E-commerce

  • Types of threats: Data Breach, Injection Attacks, Malware

  • Terms: Black Friday, Cyber Monday, checkout, loyalty program, gift card (in English only)

  • Technologies: Magento, Shopify, WooCommerce, payment gateway

  • Risk level: High or Critical

Use case example

Lucas manages security at a large Brazilian retailer. Every October, he activates a seasonal rule with Terms: Black Friday and Cyber Monday scoped to Retail. This year, the rule surfaces intelligence about a skimming campaign targeting checkout pages using a JavaScript injection technique. Lucas shares the bulletin with his development team, who audit and harden their payment flow two weeks before the sales peak.


Healthcare

Target audience

Security Analysts, Compliance Officers, Hospital IT Teams

Healthcare organizations are high-value ransomware targets due to the critical nature of their operations and the sensitivity of patient data. Rules for this sector prioritize ransomware activity, medical device vulnerabilities, and electronic health record systems.

Suggested rule configuration

  • Target industry: Healthcare and Social Assistance

  • Types of threats: Ransomware, Data Breach, Exploit Attacks

  • Technologies: Epic, Cerner, medical IoT devices, DICOM systems

  • Terms: HIPAA, patient data, electronic health record, EHR, medical device (in English only)

  • Risk level: High or Critical

Use case example

Ana is the security lead at a hospital network. She configures a rule combining Industries: Healthcare, Types of threats: Ransomware, and Technologies: Epic. When a bulletin emerges about a ransomware group specifically targeting hospital scheduling systems via unpatched VPN appliances, her team receives the alert before the campaign reaches their region. They patch affected devices that same week.


Government & Public Sector

Target audience

Government CISOs, National Cybersecurity Teams, IT Directors

Government entities are frequent targets of nation-state actors, hacktivists, and espionage campaigns. Rules for this sector emphasize geopolitical threat actors, critical infrastructure, and politically motivated attacks.

Suggested rule configuration

  • Target industry: Public Administration

  • Types of threats: Cyber Attack, Data Breach, Social Engineering

  • Threat actors: known nation-state groups relevant to your region

  • Location: your country or region

  • Terms: government, ministry, election, public infrastructure, citizen data (in English only)

  • Risk level: High or Critical

Use case example

Carlos is the CISO of a federal government agency. He sets up a rule scoped to Industry: Public Administration, Location: Brazil, and Threat actors: known APT groups active in Latin America. During an election period, the rule flags a bulletin about a disinformation and credential-phishing campaign targeting government employees. His team issues an internal advisory and activates two-factor authentication enforcement across all ministry accounts.


Technology & SaaS

Target audience

Product Security Teams, DevSecOps, Security Engineers

Technology companies and SaaS providers are targeted through their software supply chain, cloud infrastructure, and developer toolchains. Rules for this sector focus on CVEs in widely used frameworks, cloud misconfigurations, and third-party dependency attacks.

Suggested rule configuration

  • Target industry: Technology and Software

  • Types of threats: Exploit Attacks, Supply Chain Attacks, and Data Breach

  • Technologies: AWS, Azure, GCP, Docker, Kubernetes, GitHub, npm, PyPI

  • Terms: zero-day, supply chain, dependency confusion, API key exposure (in English only)

  • Risk level: High or Critical

  • My technologies: your specific stack

Use case example

Rafael leads product security at a Brazilian SaaS startup. His rule includes My technologies, AWS and Kubernetes, combined with the term "supply chain and dependency confusion. When a bulletin surfaces about a malicious npm package impersonating a popular logging library, his team is alerted within hours. They audit their package lockfiles and find no compromise but update their CI pipeline to block unsigned packages going forward.


Energy & Critical Infrastructure

Target audience

OT/ICS Security Teams, Risk Managers, CISOs

Energy companies and critical infrastructure operators face targeted attacks on industrial control systems, SCADA environments, and operational technology networks. Rules for this sector focus on ICS/OT-specific CVEs, threat actors with infrastructure mandates, and supply chain risks.

Suggested rule configuration

  • Target industry: Energy and Utilities

  • Types of threats: Cyber Attack, Exploit Attacks, Remote Code Execution

  • Technologies: SCADA, ICS, Modbus, Siemens, Schneider Electric, Honeywell

  • Threat actors: groups known to target critical infrastructure

  • Terms: power grid, pipeline, OT network, industrial control, firmware (in English only)

  • Risk level: Critical

Use case example

Fernanda is the OT security lead at a Brazilian energy utility. She configures a rule combining Industry: Energy, Technologies: SCADA and ICS, and Threat actors: groups associated with infrastructure attacks. When a new bulletin reports a campaign exploiting a known CVE in a SCADA platform used across South American utilities, she receives the alert the same day. Her team confirms the vulnerable version is in use at two substations and applies the patch within the maintenance window.


MSSPs (Managed Security Service Providers)

Target audience

SOC Analysts, Threat Intelligence Leads, Account Managers

MSSPs manage threat intelligence across multiple client environments simultaneously. The monitoring rules system supports this by allowing each analyst to follow rules independently and by enabling rule templates that can be adapted per client. MSSPs benefit from broad rules that surface cross-sector threats alongside client-specific rules for each vertical they serve.

Suggested rule configuration

  • Related to: the whole world (for cross-client threat visibility)

  • Types of threats: all relevant categories for your client base

  • Threat actors: top active groups globally and regionally

  • Risk level: High or Critical

  • Per-client rules: scoped by Industry + Location + My technologies for each account

Use case example

Beatriz leads the threat intelligence function at a Brazilian MSSP with 40 clients across finance, retail, and healthcare. She maintains a global rule for cross-sector intelligence, plus three client-specific rules for her highest-risk accounts. When a ransomware bulletin affecting the healthcare sector is published on a Tuesday morning, her rule surfaces it immediately. By noon, she has briefed two healthcare clients and one fintech client whose infrastructure overlaps with the affected vendor.


Telecommunications

Target audience

Security Operations, Network Security Teams, CISOs

Telecom providers are targeted for subscriber data, SS7 vulnerabilities, and network infrastructure attacks. Rules in this sector benefit from coverage of protocol-level exploits, insider threat indicators, and large-scale data breach activity.

Suggested rule configuration

  • Target industry: Telecommunications

  • Types of threats: Data Breach, Exploit Attacks, and Cyber Attack

  • Terms: SS7, SIM swap, subscriber data, VoIP, roaming, MVNO (in English only)

  • Technologies: network management platforms, billing systems

  • Risk level: High or Critical

Use case example

Diego manages security at a regional telecom operator. He configures a rule with Industry: Telecommunications and Terms: SS7 and SIM swap. A bulletin surfaces reporting a SIM swap-as-a-service operation targeting telecom subscribers in Latin America, with indicators pointing to insider access at the carrier level. Diego escalates internally and initiates an access audit on privileged billing system accounts.


Education

Target audience

University IT Security, K-12 Security Teams, EdTech Platform Security

Educational institutions store large volumes of student and researcher data and often operate with limited security budgets. They are frequent targets for ransomware, credential phishing, and research data theft. Rules for this sector focus on phishing campaigns, exposed learning management systems, and student data breaches.

Suggested rule configuration

  • Target industry: Educational Services

  • Types of threats: Ransomware, Social Engineering, and Data Breach

  • Technologies: Canvas, Moodle, Google Workspace, Microsoft 365

  • Terms: student data, FERPA, learning management, university, research data (in English only)

  • Risk level: Medium, High, or Critical

Use case example

Priya is the information security officer at a large university. She sets up a rule scoped to Industry: Educational Services, Technologies: Canvas and Google Workspace, and Types of threats: Ransomware and Social Engineering. A bulletin reports a spear-phishing campaign targeting university faculty credentials to access grant management portals. Priya issues a targeted awareness alert to research faculty and works with IT to enforce MFA on grant system logins.


Entertainment, Media & iGaming

Target audience

Platform Security, Trust & Safety, Anti-Fraud Teams

Entertainment and gaming platforms face account takeover campaigns, cheating infrastructure, DDoS attacks, and fraud targeting in-game economies and payment systems. iGaming platforms carry additional regulatory risk around player data. Rules for this sector benefit from terms specific to gaming fraud and platform abuse.

Suggested rule configuration

  • Target industry: Entertainment, Arts, and Recreation

  • Types of threats: Malware, Cyber Attack, Data Breach

  • Terms: account takeover, ATO, credential stuffing, in-game currency, cheat engine, bonus abuse (in English only)

  • Technologies: game server platforms, streaming infrastructure, payment processors

  • Threat actors: groups known for credential theft and account fraud

  • Risk level: High or Critical

Use case example

Thiago leads security at a Brazilian iGaming platform. He configures a rule combining Industry: Entertainment, Terms: account takeover and credential stuffing, and Threat actors: groups associated with ATO campaigns. A new bulletin details a credential stuffing toolkit being sold in underground forums, specifically targeting Brazilian gaming platforms. Thiago activates rate limiting on login endpoints and coordinates with the fraud team to flag accounts with anomalous login patterns before any player reports losses.


If you have any questions, feel free to reach out at [email protected] 😊

Did this answer your question?