Category: Threat Intelligence
-
What Is Threat Intelligence? Definition and Examples
Key Takeaways Threat intelligence is the output of analysis based on identification, collection, and enrichment of relevant data and information. Always keep quantifiable business objectives in mind, and avoid producing intelligence “just in case.” Threat intelligence falls into two categories. Operational intelligence is produced by computers, whereas strategic intelligence is produced by human analysts. The…
-
How to Maximize the Return From Your Threat Intelligence Reporting
Key Takeaways Reporting is always limited by the quality of your intelligence. Make sure you’re providing genuine value, not just filling pages. If you want to maximize the value of your threat intelligence, you need to share it as widely within your organization as possible. You never know who might find it useful. Ask every…
-
Lab Test Reveals 10x Productivity Gain From Real-Time Threat Intelligence for SIEMs
Key Takeaways Independent test shows applying real-time threat intelligence powered by machine learning cuts analyst time to triage a security event from a firewall log from three minutes to 1.2 seconds on average (in a controlled environment), resulting in a 10x gain in productivity. A typical organization with only 100 devices could generate over 2,500…
-
How TIAA Uses Threat Intelligence to Enhance Security Awareness
Security awareness and strategic threat intelligence are mandatory elements of any organization’s ability to ward off cyber events. The threat landscape can appear vast and unwieldy, putting additional barriers in the way of creating a successful threat intelligence program. During a recent webinar, Joe Walbert and Mike Kirk, senior information security analysts with TIAA, explained…
-
Enabling OSINT in Activity Based Intelligence (ABI)
Activity Based Intelligence, or ABI, is an intelligence methodology developed out of the wars in Iraq and Afghanistan used to discover and disambiguate entities (e.g., people of interest) in an increasingly data-rich environment (most of it unclassified and open source). It is geospatial in nature, because it seeks to link entities and events through their…
-
Turbocharge Your Threat Hunting Capability With Intelligent TTP Alerting
Every hour of every day you are either hunting or being hunted. The only question you have to ask is which side do you want to be on?Eric Cole, PhD, SANS Analyst and Network Security Expert 86% of IT professionals say that their organization is now involved in some kind of threat hunting. Today, businesses…
-
Proactive Defense: Understanding the 4 Main Threat Actor Types
Key Takeaways Understanding the four main threat actor types is essential to proactive defense. Cyber criminals are motivated by money, so they’ll attack if they can profit. Hacktivists want to undermine your reputation or destabilize your operations. Vandalism is their preferred means of attack. State-sponsored attackers are after information, and they’re in it for the…
-
Top 6 Sources for Identifying Threat Actor TTPs
Key Takeaways Know your enemy. Understanding threat actor TTPs is essential for an effective information security program. Don’t be over reliant on a single source. The best security teams identify threat actor TTPs by combining intelligence from multiple sources. Don’t confuse data with intelligence. Sources that provide unprocessed data will end up costing you in…
-
Threat Intelligence Starter Resources
Creating a threat intelligence capability can be a challenging undertaking, and not all companies are ready for it. Businesses that run successful threat intelligence teams generally: Collect externally available data on threats and correlate it with internal events. Be aware of threats driving proactive security controls. Establish proactive internal hunting for unidentified threats. Invest in…
-
Revealing Ransomware Secrets With All-Source Analysis
Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware. Observing these, as with any type of cyber attack, can provide early warning signs of…