This is the fourth article of 5 articles series on integrating threat intelligence into daily security operations. If you have not gone through the first three articles, then I highly recommend you reading that as all articles are connected to one another in a proper sequence. In this article, I am going to talk about the effectiveness of the analysis process. Here is article 1, article 2 and article 3.
Everything about threat intelligence, blue team, red team, pentesting, security audit, security review, testing and assessment.
Showing posts with label intelligence. Show all posts
Showing posts with label intelligence. Show all posts
Thursday, September 26, 2019
Integrate Threat Intelligence program into your daily security operations - Phase 3 - Effectiveness of the Analysis Process
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Tuesday, September 17, 2019
Integrate Threat Intelligence program into your daily security operations - Phase 2 - Collecting Intelligence
This is the third article of 5 articles series on threat integrating threat intelligence into daily security operations. If you have not gone through the first two articles, then I highly recommend you reading that as all articles are connected to one another in a proper sequence. In this article, we are going to talk about phase 2 in which we will discuss what would be the intelligence collection strategy, methods and procedures. Here is article 1 and article 2.
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Saturday, May 18, 2019
Integrate Threat Intelligence program into your daily security operations - Phase 1 - Planning and Preparation
From the last article located at here, we have now a majority of information to start the preparation and planning. In this article, I am going to explain how we can initiate the project and start preparing plans and procedures. This can be done in two phases.
Initial meetings with internal team to discuss the current threat landscape of an organisation.
Review observations that can help to prepare a perfect plan.
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Wednesday, May 15, 2019
Integrate the Threat Intelligence program into your daily security operations - Phase 0 - Introduction
There is a huge amount
of the increasing use of sophisticated malware, and often organisations fail to
understand the real intent of such activities by a large group of hackers, nation-sponsored
attacks, organized cybercrimes, cyber terrorists. These attacks result in
revenue disruption, damaging public and private reputation and demolishing
business processes and workflow.
Intelligence is staying
ahead of the next threat targeting to your organisation by implementing
protective measures to protect your brand reputation, data, people, process and
technology infrastructure. I am assuming whoever reading this article has a little bit of background knowledge on threat intelligence terminology.
Just having a Threat
intelligence product itself is not sufficient, data should be collected,
classified and correlated with hacking tools, tactics and techniques.
Labels:
anonymous,
APT,
blueteam,
cyber,
cybersecurity,
darknet,
deepweb,
edr,
hacking,
informationsecurity,
infosec,
intelligence,
malware,
redteam,
security,
threat,
threathunting,
threatintelligence,
threats
Subscribe to:
Posts (Atom)


