## Cyber Threat Intelligence - Broad Definition - Any information about threats that can assist decisions for preventing and mitigating an attack - Examples - Reading new papers - Read incident reports > “Cyber Threat intelligence is information about threats and threat actors that helps mitigate harmful events in cyberspace.” [Wikipedia, 2021; Pierluigi Paganini, 2020]. #### Threat Inelligence Type ![1648755300.png](img/1648755300.png) #### Threat Intelligence Sharing - Standardised language - **S**tructured **T**hread **I**nformation e**X**pression (STIX) - Standardised Exchange Mechanism - Trusted automated Exchange of Indicator Information (TAXII) - STIX and TAXII are to enable automated cyber threat information exchange across organisation and product boundaries ##### Structured Threat Information Expression - Designed for sharing and analysing threat intelligence - Can be understood by humans - Structured language for automation. - Can be understood by security technology - Active community of developer and analyst - International standard in OASIS ![1648755739.png](img/1648755739.png) ![1648755749.png](img/1648755749.png) ###### Flexible Sharing Models - Most sharing models are variants of these three basic models ![1648755842.png](img/1648755842.png) ![1648755851.png](img/1648755851.png) ![1648755869.png](img/1648755869.png) #### Cyber Kill Chain - Kill chain is a term used bu the US military - Lockheed Martin’s process to explain and defensively mitigate future threat - Deconstructs a threat to individual components ##### Reconnaissance - The attacker research on the target before the actual attack starts - Through Internet Search, and social media ##### Weaponisation - The attacker develops a malicious payload and send to the victim - This setp happens at the attacker side, without contact with the victim - Difficult to interrupt for prevention - No longer requires advanced skills ##### Delivery - The attacker sends the malicious payload to the victim by email or other means ##### Exploitation - Triggers the intruders’ code - Targets can be - Application or host system - An operating system feature that auto-executes code - User’s themselves ##### Installation - Installs malware, remote access Trojan or backdoor on victim system - Allows the adversary to maintain persistence inside the environment - Point in time within a much more elaborate attack process that may take months to operate ##### Command and Control - The attacker creates a C2 channel in order to control the system remotely - This step is relevant throughout the attack life-cycle, not just when malware is installed ##### Action on Objectives - The attacker takes actions to achieve his original objective inside the victim’s network - Elaborate active attack process that may take months - Information Theft - Hacker Fame / Hactivism - Defacement - Extortion - Ransomware - Nation State Leverage - Destructive malware - A point to compromise additional systems