Tidy up
This commit is contained in:
103 files changed
+3663
-3779
No files matched your search
@@ -1,23 +1,23 @@
|
||||
## Cyber Threat Intelligence
|
||||
|
||||
- Broad Definition
|
||||
- Any information about threats that can assist decisions for preventing and mitigating an attack
|
||||
- Examples
|
||||
- Reading new papers
|
||||
- Read incident reports
|
||||
- Any information about threats that can assist decisions for preventing and mitigating an attack
|
||||
- Examples
|
||||
- Reading new papers
|
||||
- Reading incident reports
|
||||
|
||||
> “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020].
|
||||
|
||||
#### Threat Inelligence Type
|
||||
#### Threat Intelligence Type
|
||||
|
||||

|
||||
|
||||
#### Threat Intelligence Sharing
|
||||
|
||||
- Standardised language
|
||||
- **S**tructured **T**hread **I**nformation e**X**pression (STIX)
|
||||
- **S**tructured **T**hreat **I**nformation e**X**pression (STIX)
|
||||
- Standardised Exchange Mechanism
|
||||
- Trusted automated Exchange of Indicator Information (TAXII)
|
||||
- Trusted automated Exchange of Indicator Information (TAXII)
|
||||
- STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries
|
||||
|
||||
##### Structured Threat Information Expression
|
||||
@@ -25,8 +25,8 @@
|
||||
- Designed for sharing and analysing threat intelligence
|
||||
- Can be understood by humans
|
||||
- Structured language for automation.
|
||||
- Can be understood by security technology
|
||||
- Active community of developer and analyst
|
||||
- Can be understood by security technology
|
||||
- Active community of developers and analysts
|
||||
- International standard in OASIS
|
||||
|
||||

|
||||
@@ -45,19 +45,19 @@
|
||||
|
||||
#### Cyber Kill Chain
|
||||
|
||||
- Kill chain is a term used bu the US military
|
||||
- Kill chain is a term used by the US military
|
||||
- Lockheed Martin’s process to explain and defensively mitigate future threat
|
||||
- Deconstructs a threat to individual components
|
||||
|
||||
##### Reconnaissance
|
||||
|
||||
- The attacker research on the target before the actual attack starts
|
||||
- The attacker researches the target before the actual attack starts
|
||||
- Through Internet Search, and social media
|
||||
|
||||
##### Weaponisation
|
||||
|
||||
- The attacker develops a malicious payload and send to the victim
|
||||
- This setp happens at the attacker side, without contact with the victim
|
||||
- The attacker develops a malicious payload and sends it to the victim
|
||||
- This step happens on the attacker’s side, without contact with the victim
|
||||
- Difficult to interrupt for prevention
|
||||
- No longer requires advanced skills
|
||||
|
||||
@@ -69,9 +69,9 @@
|
||||
|
||||
- Triggers the intruders’ code
|
||||
- Targets can be
|
||||
- Application or host system
|
||||
- An operating system feature that auto-executes code
|
||||
- User’s themselves
|
||||
- Application or host system
|
||||
- An operating system feature that auto-executes code
|
||||
- Users themselves
|
||||
|
||||
##### Installation
|
||||
|
||||
@@ -88,9 +88,9 @@
|
||||
|
||||
- The attacker takes actions to achieve his original objective inside the victim’s network
|
||||
- Elaborate active attack process that may take months
|
||||
- Information Theft
|
||||
- Hacker Fame / Hactivism - Defacement
|
||||
- Extortion - Ransomware
|
||||
- Nation State Leverage
|
||||
- Destructive malware
|
||||
- A point to compromise additional systems
|
||||
- Information Theft
|
||||
- Hacker Fame / Hacktivism - Defacement
|
||||
- Extortion - Ransomware
|
||||
- Nation State Leverage
|
||||
- Destructive malware
|
||||
- A point to compromise additional systems
|
||||
Reference in new issue
Block a user