Threat Intelligence (TI) is a knowledgebase of tactical information about threat actors, including IP addresses, domains, URLs, and filenames, some of which may be time-sensitive. Used correctly, TI supports SIEM correlations, threat hunting, reporting, situational dashboards, and proactive planning, though it is not perfect and should be verified. #CozyBear #APT32
Keypoints
- TI is a knowledgebase of tactical information about threat actors, including IP addresses, domain names, URLs, and filenames, with potential time-sensitivity.
- TTPs, IOCs and APTs are key TI concepts: TTPs describe methods used; IOCs are indicators; APTs are notable threat groups.
- TI can be used in SIEM correlations to trigger alerts when logs match TI indicators.
- Threat hunting often involves comparing security logs with TI to identify known bad actors.
- TI supports reporting and situational awareness dashboards to provide broader perspectives on suspicious activity.
- TI data quality varies; attackers may reuse IPs, making TI hit-or-miss at times.
- Free TI sources may be less well-maintained than paid sources, and validation is important; always verify TI findings.
MITRE Techniques
- [T1566] Phishing β βFor example, if a state-sponsored Russian hacking group is known to perform phishing attacks followed by ransomware and only attack government institutions, that group of information may be considered a TTP.β
- [T1583] Acquire Infrastructure β βIP address is known to be associated with ATT&CKβs threat actor group APT32, then that information can be included in the TI results.β
Indicators of Compromise
- [IP Address] TI-related indicators used in monitoring β 203.0.113.5, 198.51.100.7, and 2 more IPs
- [Domain] Domains that may be associated with TI indicators β malicious.example.com, bad.example.org, and 1 more domain
- [URL] URLs referenced or used as indicators β https://www.trustwave.com/en-us/resources/blogs/spiderlabs-blog/the-underdog-of-cybersecurity-uncovering-hidden-value-in-threat-intelligence/, https://github.com/SpiderLabs/zpminternational, and 0 more URLs
- [File Name] Filenames that appear as indicators β Image 1 Microsoft Sentinel Threat Intelligence Dashboard. Courtesy Microsoft.jpg, OTSMD.jpg, and 2 more filenames