This commit is contained in:
John Gatward committed 2026-10-04 15:24:17 +01:00
1 parent d0f27f276b
commit d6f54d4ec2
103 files changed
+3663 -3779

No files matched your search

@@ -1,23 +1,23 @@
## Cyber Threat Intelligence
- Broad Definition
- Any information about threats that can assist decisions for preventing and mitigating an attack
- Examples
- Reading new papers
- Read incident reports
- Any information about threats that can assist decisions for preventing and mitigating an attack
- Examples
- Reading new papers
- Reading incident reports
> “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
#### Threat Inelligence Type
#### Threat Intelligence Type
![1648755300.png](img/1648755300.png)
#### Threat Intelligence Sharing
- Standardised language
- **S**tructured **T**hread **I**nformation e**X**pression (STIX)
- **S**tructured **T**hreat **I**nformation e**X**pression (STIX)
- Standardised Exchange Mechanism
- Trusted automated Exchange of Indicator Information (TAXII)
- Trusted automated Exchange of Indicator Information (TAXII)
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
##### Structured Threat Information Expression
@@ -25,8 +25,8 @@
- Designed for sharing and analysing threat intelligence
- Can be understood by humans
- Structured language for automation.
- Can be understood by security technology
- Active community of developer and analyst
- Can be understood by security technology
- Active community of developers and analysts
- International standard in OASIS
![1648755739.png](img/1648755739.png)
@@ -45,19 +45,19 @@
#### Cyber Kill Chain
- Kill chain is a term used bu the US military
- Kill chain is a term used by the US military
- Lockheed Martin’s process to explain and defensively mitigate future threat
- Deconstructs a threat to individual components
##### Reconnaissance
- The attacker research on the target before the actual attack starts
- The attacker researches the target before the actual attack starts
- Through Internet Search, and social media
##### Weaponisation
- The attacker develops a malicious payload and send to the victim
- This setp happens at the attacker side, without contact with the victim
- The attacker develops a malicious payload and sends it to the victim
- This step happens on the attacker’s side, without contact with the victim
- Difficult to interrupt for prevention
- No longer requires advanced skills
@@ -69,9 +69,9 @@
- Triggers the intruders’ code
- Targets can be
- Application or host system
- An operating system feature that auto-executes code
- User’s themselves
- Application or host system
- An operating system feature that auto-executes code
- Users themselves
##### Installation
@@ -88,9 +88,9 @@
- The attacker takes actions to achieve his original objective inside the victim’s network
- Elaborate active attack process that may take months
- Information Theft
- Hacker Fame / Hactivism - Defacement
- Extortion - Ransomware
- Nation State Leverage
- Destructive malware
- A point to compromise additional systems
- Information Theft
- Hacker Fame / Hacktivism - Defacement
- Extortion - Ransomware
- Nation State Leverage
- Destructive malware
- A point to compromise additional systems