Skip to main content

GTS

A Leading Egyptian Bank: Elevating Threat Intelligence Maturity From Mandiant Fusion to Google Threat Intelligence (GTI)

Country
Cairo, Egypt 

Sector
Banking & Financial Services

# of Employees
500+

Vendor
Google- Mandiant

Technology 
Cybersecurity, Threat Intelligence

Summary:

A leading Egyptian bank partnered with GTS Egypt to upgrade its threat intelligence capability from Mandiant Advantage (Fusion) to Google Threat Intelligence (GTI), consolidating Mandiant’s frontline threat research with Google’s global visibility, VirusTotal community intelligence, and Gemini-powered analysis into a single, unified platform.
The upgrade was driven by the need to close visibility gaps left by a single-source intelligence feed, reduce the manual effort required to correlate indicators across tools, and align the bank’s threat intelligence posture with CBE expectations for continuous, current coverage of the sector’s threat landscape.

Customer Challenges

Threat Intelligence:

Fragmented threat intelligence sources increased analyst triage time and left visibility gaps across the SOC.

Limited Correlation:

Limited correlation between Mandiant’s frontline intelligence and broader open-source and community signals such as VirusTotal reduced confidence in indicator scoring.

Regulatory Expectation:

Regulatory expectations from CBE called for demonstrable, current threat intelligence coverage aligned to the banking sector’s evolving threat landscape.

SOC Alert Overload:

Growing alert volumes outpaced the SOC’s manual triage capacity, with minimal AI-assisted enrichment to accelerate analyst decision-making.

GTS Core Solution

From Mandiant Advantage (Fusion) to Google Threat Intelligence:
  • Current-state assessment of Mandiant Fusion feeds, use cases, and SOC integration points (SIEM/SOAR).
  • Licensing and entitlement mapping from Mandiant Advantage to the GTI platform.
  • Integration of GTI with the bank’s existing SIEM/SOAR stack for automated IOC enrichment and alert triage.
  • Onboarding of VirusTotal Enterprise intelligence and Gemini-assisted analysis workflows for the SOC team.
  • Knowledge transfer and hands-on enablement sessions for the bank’s SOC analysts and threat intel function.

Results and & Business Outcomes

  • Mean time to triage (MTTT) for threat intel-driven alerts dropped as automated enrichment replaced manual indicator lookups.
  • IOC and TTP coverage expanded significantly through the combination of Mandiant frontline intelligence, VirusTotal community signals, and Google’s global telemetry.
  • Analyst productivity improved as Gemini-assisted enrichment and summarization reduced time spent on first-pass alert analysis.
  • The bank strengthened its audit and compliance posture, with clearer evidence of continuous, current threat intelligence coverage for CBE reporting.